Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-17659
HistoryMar 16, 2023 - 12:00 a.m.

Siemens Mendix SAML Module Certification Bypass Vulnerability (CNVD-2023-17659)

2023-03-1600:00:00
China National Vulnerability Database
www.cnvd.org.cn
8
siemens mendix
saml module
certification bypass
vulnerability
cnvd-2023-17659
authentication
cloud applications
identity provider
saml 2.0
shibboleth
exploitation

0.001 Low

EPSS

Percentile

46.4%

The Mendix SAML Module allows the use of SAML to authenticate users in cloud applications. The module can communicate with any identity provider that supports SAML 2.0 or Shibboleth. An authentication bypass vulnerability exists in Siemens Mendix SAML Module, which stems from inadequate validation of SAML assertions and can be exploited by an attacker to bypass authentication and access the application.

0.001 Low

EPSS

Percentile

46.4%

Related for CNVD-2023-17659