Improper access control in picketlink - CVE-2015-0277
Published: April 10, 2025
Vulnerability details
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to Service Provider (SP) in PicketLink does not ensure that it is a member of an Audience element when an AudienceRestriction is specified. A remote user can log in to other users' accounts via a crafted SAML assertion.
Affected software
IBM Business Automation Manager Open Editions
How to mitigate CVE-2015-0277
IBM Business Automation Manager Open Editions - update to 8.0.7