Picketlink is an identity and access management framework that provides authentication and authorization capabilities for enterprise applications, with its vulnerability footprint concentrated in the core Picketlink product itself. The observed weakness classes center on improper access control, reflecting the authentication and authorization logic inherent to identity middleware. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Picketlink over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-6254MEDIUM The (1) Service Provider (SP) and (2) Identity Provider (IdP) in PicketLink before 2.7.0 does not ensure that the Destination attribute in a Response element in a SAML assertion ma | Aug 17, 2015 | 6.0 | 17 | NO | NO |
CVE-2015-0277MEDIUM The Service Provider (SP) in PicketLink before 2.7.0 does not ensure that it is a member of an Audience element when an AudienceRestriction is specified, which allows remote attack | Aug 17, 2015 | 6.0 | 17 | NO | NO |
CVE-2015-3158MEDIUM The invokeNextValve function in identity/federation/bindings/tomcat/idp/AbstractIDPValve.java in PicketLink before 2.8.0.Beta1 does not properly check role based authorization, whi | Aug 26, 2015 | 4.0 | 14 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Picketlink.
Media articles that mention a CVE ID that affects a product developed by Picketlink — matched by CVE ID, not by vendor name.