An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys, aka WCF/WIF SAML Token Authentication Bypass Vulnerability.
The product does not validate, or incorrectly validates, a certificate.
Name | Vendor | Start Version | End Version |
---|---|---|---|
.net_framework | Microsoft | 2.0-sp2 (including) | 2.0-sp2 (including) |
.net_framework | Microsoft | 3.0-sp2 (including) | 3.0-sp2 (including) |