CVE-2025-9943 is a critical SQL injection vulnerability affecting Shibboleth Service Provider versions up to 3.5.0, specifically when its replay cache uses an SQL database via the ODBC plugin. An unauthenticated attacker can exploit this via blind SQL injection in the SAML response's "ID" attribute, potentially extracting arbitrary database data. With a CVSS score of 9.1 (CRITICAL), this vulnerability is easily exploitable over the network with no user interaction. While there is no known active exploitation or public exploit code, the vulnerability has garnered some community discussion, indicating awareness of the risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 3.5.0CPE match | cpe:2.3:a:shibboleth:service_provider:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.