Lucene search

K
cve[email protected]CVE-2009-3474
HistorySep 29, 2009 - 11:30 p.m.

CVE-2009-3474

2009-09-2923:30:00
CWE-310
web.nvd.nist.gov
26
cve-2009-3474
opensaml
xmltooling
internet2
shibboleth service provider
certificate vulnerability
security application

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.4 Medium

AI Score

Confidence

Low

0.007 Low

EPSS

Percentile

80.1%

OpenSAML 2.x before 2.2.1 and XMLTooling 1.x before 1.2.1, as used by Internet2 Shibboleth Service Provider 2.x before 2.2.1, do not follow the KeyDescriptor element’s Use attribute, which allows remote attackers to use a certificate for both signing and encryption when it is designated for just one purpose, potentially weakening the intended security application of the certificate.

Affected configurations

NVD
Node
internet2opensamlMatch2.0
OR
internet2opensamlMatch2.1.0
OR
internet2opensamlMatch2.2.0
OR
internet2xmltoolingMatch1.0.1
OR
internet2xmltoolingMatch1.1.0
OR
internet2xmltoolingMatch1.1.1
OR
internet2xmltoolingMatch1.2.0
AND
internet2shibboleth-spMatch1.3.1
OR
internet2shibboleth-spMatch1.3.2
OR
internet2shibboleth-spMatch1.3b
OR
internet2shibboleth-spMatch1.3f
OR
internet2shibboleth-spMatch2.0
OR
internet2shibboleth-spMatch2.1
OR
internet2shibboleth-spMatch2.2

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.4 Medium

AI Score

Confidence

Low

0.007 Low

EPSS

Percentile

80.1%