PT-2011-1291 · Ibm · Ibm Tivoli Federated Identity Manager

Publicado

2011-08-12

·

Atualizado

2011-08-12

·

CVE-2008-7299

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions IBM Tivoli Federated Identity Manager (TFIM) version 6.2.0
Description The issue is related to an incomplete SAML 1.x browser-artifact in IBM Tivoli Federated Identity Manager (TFIM), which allows remote OpenID providers to spoof assertions. This is achieved via vectors related to the Issuer field.
Recommendations For IBM Tivoli Federated Identity Manager (TFIM) version 6.2.0, update to version 6.2.0.2 to resolve the issue.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-7299

Produtos afetados

Ibm Tivoli Federated Identity Manager