Internet2 records
8 published records for vendor internet2.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 75%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-310 Cryptographic Issues2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-1390 Weak Authentication1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-863 Incorrect Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAll records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
38Monitor | CVE-2009-3476No exploit | Buffer overflow in OpenSAML before 1.1.3 as used in Internet2 Shibboleth Service Provider software 1.3.x before 1.3.4, and XMLTooling beforeinternet2 · shibboleth-sp · CWE-119 | Critical9.3 | — | 4.1% | Sep 29, 2009 |
36Monitor | CVE-2024-39848No exploit | Internet2 Grouper before 5.6 allows authentication bypass when LDAP authentication is used in certain ways.CWE-1390 | Critical9.1 | — | 0.4% | Jun 29, 2024 |
30Monitor | CVE-2009-3474No exploit | OpenSAML 2.x before 2.2.1 and XMLTooling 1.x before 1.2.1, as used by Internet2 Shibboleth Service Provider 2.x before 2.2.1, do not follow internet2 · opensaml · CWE-310 | High7.5 | — | 1.5% | Sep 29, 2009 |
30Monitor | CVE-2009-3475No exploit | Internet2 Shibboleth Service Provider software 1.3.x before 1.3.3 and 2.x before 2.2.1, when using PKIX trust validation, does not properly internet2 · shibboleth-sp · CWE-310 | High7.5 | — | 0.9% | Sep 29, 2009 |
24Monitor | CVE-2018-19794No exploit | Cross-site scripting (XSS) vulnerability in UiV2Public.index in Internet2 Grouper 2.2 and 2.3 allows remote attackers to inject arbitrary weinternet2 · grouper · CWE-79 | Medium6.1 | — | 1.1% | Dec 3, 2018 |
21Monitor | CVE-2013-6440No exploit | The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set tshibboleth · opensaml · CWE-200 | Medium5.0 | — | 2.8% | Feb 14, 2014 |
19Monitor | CVE-2025-59714No exploit | In Internet2 Grouper 5.17.1 before 5.20.5, group admins who are not Grouper sysadmins can configure loader jobs.internet2 · grouper · CWE-863 | Medium4.9 | — | 0.3% | Sep 18, 2025 |
11Monitor | CVE-2009-3300No exploit | Multiple cross-site scripting (XSS) vulnerabilities in the Identity Provider (IdP) 1.3.x before 1.3.4 and 2.x before 2.1.5, and the Service internet2 · identity provider · CWE-79 | Low2.6 | — | 1.7% | Nov 6, 2009 |
- CVE-2009-347638Monitor
Buffer overflow in OpenSAML before 1.1.3 as used in Internet2 Shibboleth Service Provider software 1.3.x before 1.3.4, and XMLTooling before
CriticalCVSS 9.3No exploitEPSS 4%internet2 · shibboleth-spSep 29, 2009
- CVE-2024-3984836Monitor
Internet2 Grouper before 5.6 allows authentication bypass when LDAP authentication is used in certain ways.
CriticalCVSS 9.1No exploitEPSS 0%Jun 29, 2024
- CVE-2009-347430Monitor
OpenSAML 2.x before 2.2.1 and XMLTooling 1.x before 1.2.1, as used by Internet2 Shibboleth Service Provider 2.x before 2.2.1, do not follow
HighCVSS 7.5No exploitEPSS 2%internet2 · opensamlSep 29, 2009
- CVE-2009-347530Monitor
Internet2 Shibboleth Service Provider software 1.3.x before 1.3.3 and 2.x before 2.2.1, when using PKIX trust validation, does not properly
HighCVSS 7.5No exploitEPSS 1%internet2 · shibboleth-spSep 29, 2009
- CVE-2018-1979424Monitor
Cross-site scripting (XSS) vulnerability in UiV2Public.index in Internet2 Grouper 2.2 and 2.3 allows remote attackers to inject arbitrary we
MediumCVSS 6.1No exploitEPSS 1%internet2 · grouperDec 3, 2018
- CVE-2013-644021Monitor
The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set t
MediumCVSS 5.0No exploitEPSS 3%shibboleth · opensamlFeb 14, 2014
- CVE-2025-5971419Monitor
In Internet2 Grouper 5.17.1 before 5.20.5, group admins who are not Grouper sysadmins can configure loader jobs.
MediumCVSS 4.9No exploitEPSS 0%internet2 · grouperSep 18, 2025
- CVE-2009-330011Monitor
Multiple cross-site scripting (XSS) vulnerabilities in the Identity Provider (IdP) 1.3.x before 1.3.4 and 2.x before 2.1.5, and the Service
LowCVSS 2.6No exploitEPSS 2%internet2 · identity providerNov 6, 2009