CVE-2016-9814: Critical severity SimpleSAMLphp vulnerability
Incorrect signature verification
Other sources
The validateSignature method in the SAML2\Utils class in SimpleSAMLphp before 1.14.10 and simplesamlphp/saml2 library before 1.9.1, 1.10.x before 1.10.3, and 2.x before 2.3.3 allows remote attackers to spoof SAML responses or possibly cause a denial of service (memory consumption) by leveraging improper conversion of return values to boolean.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9814?
CVE-2016-9814 is considered a high severity vulnerability due to its potential for remote attackers to spoof SAML responses.
How do I fix CVE-2016-9814?
To fix CVE-2016-9814, upgrade to SimpleSAMLphp version 1.14.10 or later, or simplesamlphp/saml2 version 1.9.1, 1.10.3, or 2.3.3.
Which software is affected by CVE-2016-9814?
CVE-2016-9814 affects SimpleSAMLphp versions before 1.14.10 and simplesamlphp/saml2 library versions before 1.9.1, 1.10.3, and 2.3.3.
What types of attacks can CVE-2016-9814 enable?
CVE-2016-9814 can allow attackers to spoof SAML responses and potentially cause a denial of service.
Is CVE-2016-9814 a local or remote vulnerability?
CVE-2016-9814 is classified as a remote vulnerability, enabling attackers to exploit the flaw from a distance.