{"id":"SUSE-SU-2026:3098-1","summary":"Security update for shibboleth-sp","details":"This update for shibboleth-sp fixes the following issue:\n\n- CVE-2025-9943: SQL injection in the 'ID' attribute of the SAML response when the replay cache of the Shibboleth\n  Service Provider (SP) is configured to use an SQL database as storage service (bsc#1249394).\n","modified":"2026-07-18T08:45:08.753001799Z","published":"2026-07-17T11:39:59Z","related":["CVE-2025-9943"],"upstream":["CVE-2025-9943"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20263098-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1249394"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-9943"}],"affected":[{"package":{"name":"shibboleth-sp","ecosystem":"SUSE:Linux Enterprise Server 12 SP5-LTSS","purl":"pkg:rpm/suse/shibboleth-sp&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.5.5-6.9.1"}]}],"ecosystem_specific":{"binaries":[{"libshibsp-lite6":"2.5.5-6.9.1","libshibsp6":"2.5.5-6.9.1","shibboleth-sp":"2.5.5-6.9.1","shibboleth-sp-devel":"2.5.5-6.9.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3098-1.json"}},{"package":{"name":"shibboleth-sp","ecosystem":"SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5","purl":"pkg:rpm/suse/shibboleth-sp&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.5.5-6.9.1"}]}],"ecosystem_specific":{"binaries":[{"libshibsp-lite6":"2.5.5-6.9.1","libshibsp6":"2.5.5-6.9.1","shibboleth-sp":"2.5.5-6.9.1","shibboleth-sp-devel":"2.5.5-6.9.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3098-1.json"}}],"schema_version":"1.7.5"}