7.5

CVE-2009-3474

OpenSAML 2.x before 2.2.1 and XMLTooling 1.x before 1.2.1, as used by Internet2 Shibboleth Service Provider 2.x before 2.2.1, do not follow the KeyDescriptor element's Use attribute, which allows remote attackers to use a certificate for both signing and encryption when it is designated for just one purpose, potentially weakening the intended security application of the certificate.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Internet2Opensaml Version2.0
Internet2Opensaml Version2.1.0
Internet2Opensaml Version2.2.0
Internet2Xmltooling Version1.0.1
Internet2Xmltooling Version1.1.0
Internet2Xmltooling Version1.1.1
Internet2Xmltooling Version1.2.0
Internet2Shibboleth-sp Version1.3.1
Internet2Shibboleth-sp Version1.3.2
Internet2Shibboleth-sp Version1.3b
Internet2Shibboleth-sp Version1.3f
Internet2Shibboleth-sp Version2.0
Internet2Shibboleth-sp Version2.1
Internet2Shibboleth-sp Version2.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.29% 0.778
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P