CVE-2015-1796 describes a vulnerability in Shibboleth Identity Provider before 2.4.4 and OpenSAML Java before 2.6.5, where their PKIX trust engines improperly validate X.509 credentials. This flaw allows remote attackers to impersonate an entity by presenting a certificate issued by a shibmd:KeyAuthority trust anchor when no trusted names are configured for the entityID. The vulnerability has a CVSS score of 4.3 (Medium), indicating a network-based attack with medium complexity, requiring no authentication, and potentially leading to partial integrity impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.4.3CPE matchmatch criteria | cpe:2.3:a:shibboleth:identity_provider:*:*:*:*:*:*:*:* | ||
<= 2.6.4CPE matchmatch criteria | cpe:2.3:a:shibboleth:opensaml_java:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.