Service Provider
Vendor:
First CVE: Mar 31, 2015 · Active for 11 years
8
Total CVEs
More Total CVEs than 87% of tracked products
1.3
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 45% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Service Provider over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 31, 2015
11 years ago
Most Recent CVE
Sep 10, 2025
321 days ago
CVE Severity & Scoring
Service Provider8 CVEs
25%
63%
13%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (25.0%)
Network5 (62.5%)
Unknown1 (12.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (75.0%)
High1 (12.5%)
Unknown1 (12.5%)
User Interaction
None6 (75.0%)
Unknown1 (12.5%)
Required1 (12.5%)
Privileges Required
Low2 (25.0%)
High0 (0.0%)
None5 (62.5%)
Unknown1 (12.5%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-9943CRITICAL An SQL injection vulnerability has been identified in the "ID" attribute of the SAML response when the replay cache of the Shibboleth Service Provider (SP) is configured to use an | Sep 10, 2025 | 9.1 | 27 | NO | NO |
CVE-2010-2450HIGH The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm. It relies on the | Nov 7, 2019 | 7.5 | 25 | NO | NO |
CVE-2017-16852HIGH shibsp/metadata/DynamicMetadataProvider.cpp in the Dynamic MetadataProvider plugin in Shibboleth Service Provider before 2.6.1 fails to properly configure itself with the MetadataF | Nov 16, 2017 | 8.1 | 25 | NO | NO |
CVE-2023-22947HIGH Insecure folder permissions in the Windows installation path of Shibboleth Service Provider (SP) before 3.4.1 allow an unprivileged local attacker to escalate privileges to SYSTEM | Jan 11, 2023 | 7.3 | 24 | NO | NO |
CVE-2021-31826HIGH Shibboleth Service Provider 3.x before 3.2.2 is prone to a NULL pointer dereference flaw involving the session recovery feature. The flaw is exploitable (for a daemon crash) on sys | Apr 27, 2021 | 7.5 | 24 | NO | NO |
CVE-2019-19191HIGH Shibboleth Service Provider (SP) 3.x before 3.1.0 shipped a spec file that calls chown on files in a directory controlled by the service user (the shibd account) after installation | Nov 21, 2019 | 7.8 | 23 | NO | NO |
CVE-2021-28963MEDIUM Shibboleth Service Provider before 3.2.1 allows content injection because template generation uses attacker-controlled parameters. | Mar 22, 2021 | 5.3 | 20 | NO | NO |
CVE-2015-2684MEDIUM Shibboleth Service Provider (SP) before 2.5.4 allows remote authenticated users to cause a denial of service (crash) via a crafted SAML message. | Mar 31, 2015 | 4.0 | 14 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Service Provider
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.0 | 1 | 7.5 | 1.2% | 0 | 0 |