PT-2011-4268 · Ibm+1 · Ibm Tivoli Federated Identity Manager Business Gateway+2
Published
2011-08-12
·
Updated
2017-08-29
·
CVE-2011-3138
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Tivoli Federated Identity Manager versions 6.2.0 through 6.2.0.8
IBM Tivoli Federated Identity Manager Business Gateway versions 6.2.0 through 6.2.0.8
Description
The issue is related to the LTPA STS module support implementation, which relies on a static instance of a Java Development Kit (JDK) class. This might allow attackers to bypass LTPA token signature verification by leveraging the lack of thread safety.
Recommendations
For IBM Tivoli Federated Identity Manager versions 6.2.0 through 6.2.0.8, update to version 6.2.0.9 or later.
For IBM Tivoli Federated Identity Manager Business Gateway versions 6.2.0 through 6.2.0.8, update to version 6.2.0.9 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Tivoli Federated Identity Manager
Ibm Tivoli Federated Identity Manager Business Gateway
Java Development Kit