VendorsSimpleSAMLphpsaml2all versions
Vulnerabilities

SimpleSAMLphp SAML2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2016-9814
The validateSignature method in the SAML2\Utils class in SimpleSAMLphp before 1.14.10 and simplesamlphp/saml2 library before 1.9.1, 1.10.x before 1.10.3, and 2.x before 2.3.3 allows remote attackers to spoof SAML responses or possibly cause a denial of service (memory consumption) by leveraging improper conversion of return values to boolean.
Published 2017-02-16 · Modified
9.1EPSS 0.024
CVE-2018-7711
HTTPRedirect.php in the saml2 library in SimpleSAMLphp before 1.15.4 has an incorrect check of return values in the signature validation utilities, allowing an attacker to get invalid signatures accepted as valid by forcing an error during validation. This occurs because of a dependency on PHP functionality that interprets a -1 error code as a true boolean value.
Published 2018-03-05 · Modified
8.1EPSS 0.012
CVE-2018-6519
The SAML2 library before 1.10.4, 2.x before 2.3.5, and 3.x before 3.1.1 in SimpleSAMLphp has a Regular Expression Denial of Service vulnerability for fraction-of-seconds data in a timestamp.
Published 2018-02-02 · Modified
7.5EPSS 0.017
CVE-2023-49087
Validation of SignedInfo
Published 2023-11-30 · Modified
7.5EPSS 0.002