Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2016-4464

The application plugins in Apache CXF Fediz 1.2.x before 1.2.3 and 1.3.x before 1.3.1 do not match SAML AudienceRestriction values against configured audience URIs, which might allow remote attackers to have bypass intended restrictions and have unspecified other impact via a crafted SAML token with a trusted signature.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.021
EPSS Ranking 82.9%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
References
Products affected by CVE-2016-4464


Contact Us

Shodan ® - All rights reserved