CVE-2015-1796: Shibboleth Identity Provider

Medium severity, CVSS 4.3. EPSS: 1.3% chance of exploitation in the next 30 days.

The PKIX trust engines in Shibboleth Identity Provider before 2.4.4 and OpenSAML Java (OpenSAML-J) before 2.6.5 trust candidate X.509 credentials when no trusted names are available for the entityID, which allows remote attackers to impersonate an entity via a certificate issued by a shibmd:KeyAuthority trust anchor.

Affected products

  • Shibboleth Identity Provider: up to and including 2.4.3
  • Shibboleth Opensaml Java: up to and including 2.6.4

Published 2015-07-08. Last modified 2026-06-17.