CWE-16
ISO27001-A.14.2.5
WASC-15
OWASP 2013-A5
OWASP 2017-A6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

SAML Response Without Signature

Severity:
High
Summary

Invicti detected that the target application is vulnerable to a SAML Response without a signature.

The web application uses SAML. The web application's SAML Consumer Service doesn't require SAML Response signature. An authenticated attacker may be able to use it to escalate privileges to a high privileged user or to takeover accounts of other users in the application.

Impact

Account takeover and/or privilege escalation

Remediation

Change the configuration of the SAML service to require a valid signature for SAML Response

Required Skills for Successful Exploitation
Actions To Take
Vulnerability Index

You can search and find all vulnerabilities

Select Vulnerability
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.