Записи Internet2
8 опубликованных записей вендора internet2.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 75 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-310 Cryptographic Issues2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-1390 Weak Authentication1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-863 Incorrect Authorization1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
8 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
38Наблюдать | CVE-2009-3476Эксплойта нет | Buffer overflow in OpenSAML before 1.1.3 as used in Internet2 Shibboleth Service Provider software 1.3.x before 1.3.4, and XMLTooling beforeinternet2 · shibboleth-sp · CWE-119 | Критическая9,3 | — | 4,1 % | 29 сент. 2009 г. |
36Наблюдать | CVE-2024-39848Эксплойта нет | Internet2 Grouper before 5.6 allows authentication bypass when LDAP authentication is used in certain ways.CWE-1390 | Критическая9,1 | — | 0,4 % | 29 июн. 2024 г. |
30Наблюдать | CVE-2009-3474Эксплойта нет | OpenSAML 2.x before 2.2.1 and XMLTooling 1.x before 1.2.1, as used by Internet2 Shibboleth Service Provider 2.x before 2.2.1, do not follow internet2 · opensaml · CWE-310 | Высокая7,5 | — | 1,5 % | 29 сент. 2009 г. |
30Наблюдать | CVE-2009-3475Эксплойта нет | Internet2 Shibboleth Service Provider software 1.3.x before 1.3.3 and 2.x before 2.2.1, when using PKIX trust validation, does not properly internet2 · shibboleth-sp · CWE-310 | Высокая7,5 | — | 0,9 % | 29 сент. 2009 г. |
24Наблюдать | CVE-2018-19794Эксплойта нет | Cross-site scripting (XSS) vulnerability in UiV2Public.index in Internet2 Grouper 2.2 and 2.3 allows remote attackers to inject arbitrary weinternet2 · grouper · CWE-79 | Средняя6,1 | — | 1,1 % | 3 дек. 2018 г. |
21Наблюдать | CVE-2013-6440Эксплойта нет | The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set tshibboleth · opensaml · CWE-200 | Средняя5,0 | — | 2,8 % | 14 февр. 2014 г. |
19Наблюдать | CVE-2025-59714Эксплойта нет | In Internet2 Grouper 5.17.1 before 5.20.5, group admins who are not Grouper sysadmins can configure loader jobs.internet2 · grouper · CWE-863 | Средняя4,9 | — | 0,3 % | 18 сент. 2025 г. |
11Наблюдать | CVE-2009-3300Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in the Identity Provider (IdP) 1.3.x before 1.3.4 and 2.x before 2.1.5, and the Service internet2 · identity provider · CWE-79 | Низкая2,6 | — | 1,7 % | 6 нояб. 2009 г. |
- CVE-2009-347638Наблюдать
Buffer overflow in OpenSAML before 1.1.3 as used in Internet2 Shibboleth Service Provider software 1.3.x before 1.3.4, and XMLTooling before
КритическаяCVSS 9,3Эксплойта нетEPSS 4 %internet2 · shibboleth-sp29 сент. 2009 г.
- CVE-2024-3984836Наблюдать
Internet2 Grouper before 5.6 allows authentication bypass when LDAP authentication is used in certain ways.
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %29 июн. 2024 г.
- CVE-2009-347430Наблюдать
OpenSAML 2.x before 2.2.1 and XMLTooling 1.x before 1.2.1, as used by Internet2 Shibboleth Service Provider 2.x before 2.2.1, do not follow
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %internet2 · opensaml29 сент. 2009 г.
- CVE-2009-347530Наблюдать
Internet2 Shibboleth Service Provider software 1.3.x before 1.3.3 and 2.x before 2.2.1, when using PKIX trust validation, does not properly
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %internet2 · shibboleth-sp29 сент. 2009 г.
- CVE-2018-1979424Наблюдать
Cross-site scripting (XSS) vulnerability in UiV2Public.index in Internet2 Grouper 2.2 and 2.3 allows remote attackers to inject arbitrary we
СредняяCVSS 6,1Эксплойта нетEPSS 1 %internet2 · grouper3 дек. 2018 г.
- CVE-2013-644021Наблюдать
The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set t
СредняяCVSS 5,0Эксплойта нетEPSS 3 %shibboleth · opensaml14 февр. 2014 г.
- CVE-2025-5971419Наблюдать
In Internet2 Grouper 5.17.1 before 5.20.5, group admins who are not Grouper sysadmins can configure loader jobs.
СредняяCVSS 4,9Эксплойта нетEPSS 0 %internet2 · grouper18 сент. 2025 г.
- CVE-2009-330011Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in the Identity Provider (IdP) 1.3.x before 1.3.4 and 2.x before 2.1.5, and the Service
НизкаяCVSS 2,6Эксплойта нетEPSS 2 %internet2 · identity provider6 нояб. 2009 г.