CVE-2015-1796

medium

Description

The PKIX trust engines in Shibboleth Identity Provider before 2.4.4 and OpenSAML Java (OpenSAML-J) before 2.6.5 trust candidate X.509 credentials when no trusted names are available for the entityID, which allows remote attackers to impersonate an entity via a certificate issued by a shibmd:KeyAuthority trust anchor.

References

https://shibboleth.net/community/advisories/secadv_20150225.txt

http://www.securityfocus.com/bid/75370

http://rhn.redhat.com/errata/RHSA-2015-1177.html

http://rhn.redhat.com/errata/RHSA-2015-1176.html

Details

Source: Mitre, NVD

Published: 2015-07-08

Updated: 2026-05-06

Risk Information

CVSS v2

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 4.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Severity: Medium

EPSS

EPSS: 0.00235