Impact
A flaw in the Picketlink Federation SAML component allows an unauthenticated attacker to send a forged SAML assertion that the system accepts without any verification or validation, enabling the attacker to authenticate as any desired principal in any role. This results in a complete loss of authentication integrity, which could lead to information disclosure and unauthorized execution of restricted operations within the affected application.
Affected Systems
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 (including version 7.4.25) and Red Hat JBoss Enterprise Application Platform 8 are affected. These products include the Picketlink Federation SAML module that processes unsolicited responses without validation.
Risk and Exploitability
The CVSS score of 9.8 confirms critical severity. The EPSS score of <1% indicates a very low probability of exploitation under typical conditions, yet the flaw provides a trivial authentication bypass once an attacker can reach the SAML endpoint. The vulnerability is not listed in the CISA KEV catalog, but the high CVSS motivates immediate action. Based on the description, it is inferred that the likely attack vector is a remote attacker submitting a forged SAML assertion that the server accepts as a legitimate response to an unsolicited request.
OpenCVE Enrichment