CVE-2012-5353: Eduserv Openathens Service Provider

Medium severity, CVSS 5.8. EPSS: 2.2% chance of exploitation in the next 30 days.

Eduserv OpenAthens SP 2.0 for Java allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack."

Affected products

  • Eduserv Openathens Service Provider: version 2.0 only

Published 2012-10-09. Last modified 2026-06-16.