Impact
A flaw in the Picketlink Federation SAML component allows an unauthenticated attacker to send a forged SAML assertion that the system accepts without any verification or validation, enabling the attacker to authenticate as any desired principal in any role. This results in a complete loss of authentication integrity, which could lead to information disclosure and unauthorized execution of restricted operations within the affected application.
Affected Systems
All versions of Red Hat JBoss Enterprise Application Platform 7 and Red Hat JBoss Enterprise Application Platform 8 that include the Picketlink Federation SAML module are susceptible. The issue is present in the unsolicited response handler of these products.
Risk and Exploitability
The CVSS score of 9.8 indicates the vulnerability is of critical severity. No EPSS score is available, so the exploitation probability cannot be quantified, but the lack of authentication safeguards makes the attack trivial once the attacker can reach the SAML endpoint. The vulnerability is not listed in the CISA KEV catalog, yet the high CVSS score suggests urgency for mitigation. The likely attack vector is a remote attacker submitting a crafted SAML response to a publicly reachable service that accepts unsolicited responses.
OpenCVE Enrichment