CVE-2015-5372

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
28/09/2015
Last modified:
12/04/2025

Description

The SAML 2.0 implementation in AdNovum nevisAuth 4.13.0.0 before 4.18.3.1, when using SAML POST-Binding, does not match all attributes of the X.509 certificate embedded in the assertion against the certificate from the identity provider (IdP), which allows remote attackers to inject arbitrary SAML assertions via a crafted certificate.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:adnovum:nevisauth:*:*:*:*:*:*:*:* 4.18.3.0 (including)