CVE-2015-5253: Apache Cxf
Medium severity, CVSS 4.0. EPSS: 5.7% chance of exploitation in the next 30 days.
The SAML Web SSO module in Apache CXF before 2.7.18, 3.0.x before 3.0.7, and 3.1.x before 3.1.3 allows remote authenticated users to bypass authentication via a crafted SAML response with a valid signed assertion, related to a "wrapping attack."
Affected products
- Apache Cxf: before 2.7.18 (fixed in 2.7.18); from 3.0.0, before 3.0.7 (fixed in 3.0.7); from 3.1.0, before 3.1.3 (fixed in 3.1.3)
Published 2015-11-18. Last modified 2026-06-17.