VULNERABILITY INTELLIGENCE

CVE-2016-10149

CVSS score7.5 HIGH
EPSS probability5.02%
CISA KEVNot currently listed
Published2017-03-24
Last modified2026-06-17
CVSS vectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

XML External Entity (XXE) vulnerability in PySAML2 4.4.0 and earlier allows remote attackers to read arbitrary files via a crafted SAML XML request or response.

Weakness classification

  • CWE-611: Improper Restriction of XML External Entity Reference

Primary references