← Back

CVE-2015-5372

nvd nist
Published: Sep 28, 2015Modified: May 6, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:P/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

The SAML 2.0 implementation in AdNovum nevisAuth 4.13.0.0 before 4.18.3.1, when using SAML POST-Binding, does not match all attributes of the X.509 certificate embedded in the assertion against the certificate from the identity provider (IdP), which allows remote attackers to inject arbitrary SAML assertions via a crafted certificate.

Affected (1)

Products: Adnovum: Nevisauth
1 product
Nevisauth
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 4.18.3.0

Timeline

No history available yet.