Our takeCERT-Bund updated its high-severity advisory on Shibboleth Service Provider. Remote unauthenticated attackers can exploit the flaw for SQL injection. Update if you run it.Cyber Resilience desk
Sources (15)
- cert_bund · cert_bund
- cert_bund · cert_bund
- cert_bund · cert_bund
- cert_bund · cert_bund
- cert_bund · cert_bund
- cert_bund · cert_bund
- cert_bund · cert_bund
- cert_bund · cert_bund
- cert_bund · cert_bund
- cert_bund · cert_bund
- cert_bund · cert_bund
- cert_bund · cert_bund
- cert_bund · cert_bund
- cert_bund · cert_bund
- cert_bund · cert_bund
What this means for you — Security leader:If you run Shibboleth Service Provider, apply the CERT-Bund–flagged update for this high-severity SQL injection; remote unauthenticated attackers can exploit it. Confirm SP instances are inventoried and patched on your identity estate.
What this means for you — Lean IT orgs:Most lean-IT shops do not run Shibboleth Service Provider themselves. If a university, parent org, or vendor handles your SSO/federation, ask them whether this SP flaw is patched.
What this means for you — MSP:Inventory client estates for Shibboleth Service Provider and push the update; this is a high-severity SQL injection reachable by remote unauthenticated attackers. Prioritize education and federation-heavy clients.
What this means for you — Researcher:CERT-Bund rates this Shibboleth SP SQL injection high (WID-SEC-2025-2031); remote anonymous exploitation is in scope per the advisory.