External risk intelligence

Shibboleth SP SQL Injection via SAML ID Attribute

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2025-9943

The Shibboleth Service Provider is an identity federation component designed specifically to be public-facing to facilitate single sign-on services and authentication between organizations and web applications. It functions as a gateway for internet-facing identity traffic, making this component a standard, public-accessible point in common deployment architectures.

SQL Injection

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability in the Shibboleth Service Provider allows unauthenticated attackers to extract sensitive data from databases if specific configurations are in place. This issue stems from how the system handles identity information within SAML responses, potentially exposing arbitrary data. The primary concern is confirming if this specific configuration exists within our environment.

  • Attackers can steal database information.
  • It affects public-facing identity gateways.
  • Confirm exposure in your environment.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can exploit this issue by sending a specially crafted SAML response. This manipulates the "ID" attribute, leading to blind SQL injection if the Shibboleth Service Provider is configured to use an SQL database for its replay cache and the ODBC plugin is enabled. The vulnerability could allow an attacker to extract sensitive data from the database.

  • No authentication required.
  • Triggered by a malicious SAML response ID.
  • Risk of arbitrary data extraction.

Live Threat

Current exploitation, exposure, and threat context

When the Shibboleth Service Provider's replay cache is configured to use an SQL database with the ODBC plugin, an unauthenticated attacker could potentially extract arbitrary data from the database through blind SQL injection. This could occur if the database connection is not properly secured and sufficient escaping of single quotes is not implemented.

  • Database data could be exposed.
  • Via blind SQL injection in SAML responses.
  • Arbitrary data extraction from the database.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Shibboleth Service Provider (SP) infrastructure teams or identity and access management (IAM) teams are likely responsible for addressing this SQL injection vulnerability. The first practical step is to inventory all Shibboleth SP instances, determine which ones use an SQL database for replay caching with the ODBC plugin, and assess their external reachability and business criticality. Once identified, confirm the accountable owner and then plan remediation activities, potentially involving coordination with the Shibboleth vendor and database administrators, within a scheduled maintenance window.

  • Owner: Infrastructure or IAM teams.
  • Verify: SQL replay cache, ODBC plugin usage.
  • Action: Plan remediation for critical instances.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Shibboleth Service Provider?

Shibboleth Service Provider is a software component used by organizations to enable Single Sign-On (SSO). It acts as a gateway that processes identity information, allowing users to authenticate across different web applications by facilitating the exchange of security tokens.

What does CVE-2025-9943 mean?

This CVE identifies a security weakness known as SQL Injection, classified as CWE-89. It happens when software fails to properly clean input data before using it in database queries. In this case, the system does not sufficiently escape characters in SAML responses, potentially allowing an attacker to manipulate those queries to access data they should not see.

How is this SQL injection triggered?

An attacker triggers this by sending a malicious SAML response containing a specially crafted ID attribute. This only affects systems where the replay cache is configured to use an SQL database with the ODBC plugin enabled. It will not trigger this vulnerability if you are using a different storage method or if the ODBC plugin is disabled.

Why is this a risk for internet-facing systems?

According to Halo Surface Signal, the Shibboleth Service Provider is designed to be public-facing to facilitate authentication between different organizations. Because it is meant to be accessible to internet traffic, any system using the vulnerable configuration is reachable by unauthenticated users, increasing the importance of checking your deployment.

How do I check if I am affected?

Start by identifying all instances of the Shibboleth Service Provider in your environment. For each instance, check if it is configured to use an SQL database for the replay cache and if the ODBC plugin is active. If both are true, consult with your IAM or infrastructure team to plan a review or update based on the vendor's guidance.

References