CVE-2012-5353: Eduserv Openathens Service Provider
Medium severity, CVSS 5.8. EPSS: 2.2% chance of exploitation in the next 30 days.
Eduserv OpenAthens SP 2.0 for Java allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack."
Affected products
- Eduserv Openathens Service Provider: version 2.0 only
Published 2012-10-09. Last modified 2026-06-16.