Skip to content
Noroxi

picketlink records

3 published records for vendor picketlink.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
No record has entered KEV

Records by year

    Bar: total · dark part: CISA KEV.

    Recurring classes

    The weakness classes this vendor ships most often: where to look.

    CWE

    All records

    3 records
    • CVE-2015-0277
      25Monitor

      The Service Provider (SP) in PicketLink before 2.7.0 does not ensure that it is a member of an Audience element when an AudienceRestriction

      MediumCVSS 6.0No exploitEPSS 2%

      picketlink · picketlinkAug 17, 2015

    • CVE-2015-6254
      25Monitor

      The (1) Service Provider (SP) and (2) Identity Provider (IdP) in PicketLink before 2.7.0 does not ensure that the Destination attribute in a

      MediumCVSS 6.0No exploitEPSS 2%

      picketlink · picketlinkAug 17, 2015

    • CVE-2015-3158
      17Monitor

      The invokeNextValve function in identity/federation/bindings/tomcat/idp/AbstractIDPValve.java in PicketLink before 2.8.0.Beta1 does not prop

      MediumCVSS 4.0No exploitEPSS 2%

      picketlink · picketlinkAug 26, 2015