The vulnerabilities are rather to easy to address as a service provider. It boils down to 1) Use Https, 2) Assert both the request expiration and that you (the service) are the intended recipient of the request, and 3) Assert the signature (using the metadata you received from the identity provider through a trusted channel). I don't know why people say SAML is complex or hard, it's just you accepting a redirect from an identity provider with an XML payload you validate against.