PT-2015-5836 · Shibboleth · Shibboleth Service Provider

Brett Slaughter

·

Published

2015-03-28

·

Updated

2016-12-03

·

CVE-2015-2684

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Shibboleth Service Provider (SP) versions prior to 2.5.4
Description The issue allows remote authenticated users to cause a denial of service, resulting in a crash, by sending a crafted SAML message.
Recommendations For versions prior to 2.5.4, update to version 2.5.4 or later to resolve the issue.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-2684
DLA-259-1
DSA-3207-1
MGASA-2015-0148

Affected Products

Shibboleth Service Provider