Описание
An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with SAML single sign-on enabled.
Уязвимые конфигурации
Конфигурация 1Версия до 11.3.6 (исключая)Версия от 12.0.0 (включая) до 12.0.3 (исключая)
Одно из
cpe:2.3:a:progress:marklogic_server:*:*:*:*:*:*:*:*
cpe:2.3:a:progress:marklogic_server:*:*:*:*:*:*:*:*
EPSS
Процентиль: 25%
0.00317
Низкий
9.1 Critical
CVSS3
Дефекты
CWE-347
Связанные уязвимости
CVSS3: 9.1
github
около 2 месяцев назад
An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with SAML single sign-on enabled.
EPSS
Процентиль: 25%
0.00317
Низкий
9.1 Critical
CVSS3
Дефекты
CWE-347