PT-2012-1516 · Ibm · Ibm Tivoli Federated Identity Manager Business Gateway+1

Publicado

2012-01-04

·

Atualizado

2017-08-17

·

CVE-2011-1386

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions IBM Tivoli Federated Identity Manager (TFIM) and Tivoli Federated Identity Manager Business Gateway (TFIMBG) versions 6.1.1, 6.2.0, and 6.2.1
Description The issue arises from improper handling of signature validations based on SAML 1.0, 1.1, and 2.0, allowing remote attackers to bypass intended authentication or authorization requirements via a non-conforming SAML signature.
Recommendations For versions 6.1.1, 6.2.0, and 6.2.1, consider implementing additional validation checks for SAML signatures to ensure conformity with SAML 1.0, 1.1, and 2.0 standards until a patch is available. As a temporary workaround, restrict access to sensitive resources that rely on SAML-based authentication to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-1386

Produtos afetados

Ibm Tivoli Federated Identity Manager
Ibm Tivoli Federated Identity Manager Business Gateway