Critical
Low
Medium
CVE-2025-9943
Overview
An SQL injection vulnerability has been identified in the "ID" attribute of the SAML response when the replay cache of the Shibboleth Service Provider (SP) is configured to use an SQL database as storage service. An unauthenticated attacker can exploit this issue via blind SQL injection, allowing fo...
Critical
Low
Medium
No items found.