Vulnerabilities (CVE)

Filtered by vendor Eduserv Subscribe
Filtered by product Openathens Service Provider
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2012-5353 1 Eduserv 1 Openathens Service Provider 2024-11-21 5.8 MEDIUM N/A
Eduserv OpenAthens SP 2.0 for Java allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack."