Vulnerability Description
Eduserv OpenAthens SP 2.0 for Java allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack."
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Eduserv | Openathens Service Provider | 2.0 |
Related Weaknesses (CWE)
References
- http://status.openathens.net/adv.php
- http://www.nds.rub.de/media/nds/veroeffentlichungen/2012/08/22/BreakingSAML_3.pd
- http://status.openathens.net/adv.php
- http://www.nds.rub.de/media/nds/veroeffentlichungen/2012/08/22/BreakingSAML_3.pd
FAQ
What is CVE-2012-5353?
CVE-2012-5353 is a vulnerability with a CVSS score of 5.8 (MEDIUM). Eduserv OpenAthens SP 2.0 for Java allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack."
How severe is CVE-2012-5353?
CVE-2012-5353 has been rated MEDIUM with a CVSS base score of 5.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-5353?
Check the references section above for vendor advisories and patch information. Affected products include: Eduserv Openathens Service Provider.