Internet2

    Dashboard / Vendors

    Products: 6
    Vulnerabilities: 8
    Known Exploited: 0
    2
    Critical Level Threats
    2
    High Level Threats
    3
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-59714

    In Internet2 Grouper 5.17.1 before 5.20.5, group admins who are not Grouper sysadmins can configure loader jobs.

    Last Modified: Oct 08, 2025
    Published: Sep 19, 2025

    CVE-2024-39848

    Internet2 Grouper before 5.6 allows authentication bypass when LDAP authentication is used in certain ways. This is related to internet2.middleware.grouper.ws.security.WsGrouperLdapAuthentication and the use of the UyY29r password for the M3vwHr account. This also affects "Grouper for Web Services" before 4.13.1.

    Last Modified: Apr 15, 2026
    Published: Jun 29, 2024

    CVE-2018-19794

    Cross-site scripting (XSS) vulnerability in UiV2Public.index in Internet2 Grouper 2.2 and 2.3 allows remote attackers to inject arbitrary web script or HTML via the code parameter.

    Last Modified: Nov 21, 2024
    Published: Dec 03, 2018

    CVE-2013-6440

    Java: XML eXternal Entity (XXE) flaw in ParserPool and Decrypter

    Last Modified: Apr 11, 2025
    Published: Dec 11, 2013

    CVE-2009-3300

    Multiple cross-site scripting (XSS) vulnerabilities in the Identity Provider (IdP) 1.3.x before 1.3.4 and 2.x before 2.1.5, and the Service Provider 1.3.x before 1.3.5 and 2.x before 2.3, in Internet2 Middleware Initiative Shibboleth allow remote attackers to inject arbitrary web script or HTML via URLs that are encountered in redirections, and appear in automatically generated forms.

    Last Modified: Apr 23, 2026
    Published: Nov 06, 2009
    Items Per Page