PT-2011-1334 · Ibm · Ibm Tivoli Federated Identity Manager
Published
2011-08-12
·
Updated
2012-04-25
·
CVE-2009-5085
CVSS v2.0
2.6
Low
| Vector | AV:N/AC:H/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Tivoli Federated Identity Manager (TFIM) versions 6.2.0 through 6.2.0.1
Description
The issue allows user-assisted remote attackers to bypass intended trust restrictions. This occurs when the software, configured as an OpenID provider, fails to delete the site information cookie after a user deletes a relying-party trust entry. As a result, attackers can exploit this via vectors that trigger the absence of the consent-to-authenticate page.
Recommendations
For IBM Tivoli Federated Identity Manager (TFIM) versions 6.2.0 through 6.2.0.1, update to version 6.2.0.2 or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Tivoli Federated Identity Manager