CVE-2017-12873

critical
Published 2017-09-01 · Modified 2024-02-16
CVSS v3
9.8
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
7.5
VIR risk
9.8

Description

SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain sensitive information, gain unauthorized access, or have unspecified other impacts by leveraging incorrect persistent NameID generation when an Identity Provider (IdP) is misconfigured.

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2017-12873

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://simplesamlphp.org/security/201612-04

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/simplesamlphp/simplesamlphp/commit/90dca835158495b173808273e7df127303b8b953

OS impact

OSVersionStatusFixed in
debian debian7.0affected
debian debian8.0affected
debian debian9.0affected
debian debianbookwormfixed1.14.11-1
debian debianbullseyefixed1.14.11-1
debian debiansidfixed1.14.11-1

Package impact

EcosystemPackageVulnerableFixed
php Packagistsimplesamlphp/simplesamlphp>=1.7.0,<1.14.111.14.11

Application impact

VendorProductVersionsFixed
simplesamlphpsimplesamlphp{"startIncluding":"1.7.0","endIncluding":"1.14.10"}

References

CWEs

CWE-384

Verify integrity in audit chain (admin only). AS-IS.