Known vulnerabilities in Shibboleth Service Provider
Vendor:
Shibboleth
Software:
Shibboleth Service Provider
Software CPE:
cpe:2.3:a:shibboleth:shibboleth_service_provider:*:*:*:*:*:*:*:*
Website:
https://www.shibboleth.net/
Total vulnerabilities:
3
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (3)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU114998 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
CWE-89 | High | 3.5.1 | 09.09.2025 |
SB2025090914 SB2025090919 |
||
| #VU51583 - Improper input validation |
CWE-20 | Low | 3.2.1 | 19.03.2021 |
SB2021031904 SB2021031905 |
||
| #VU10777 - Improper Restriction of XML External Entity Reference ('XXE') CVE-2018-0489 |
CWE-611 | Low | 2.6.1 | 28.02.2018 |
SB2018022801 SB2018022803 |