PT-2012-4646 · Ibm · Ibm Tivoli Federated Identity Manager Business Gateway+1

Published

2012-10-02

·

Updated

2013-02-01

·

CVE-2012-3314

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions IBM Tivoli Federated Identity Manager (TFIM) and Tivoli Federated Identity Manager Business Gateway (TFIMBG) versions 6.1.1, 6.2.0, 6.2.1, 6.2.2
Description The issue allows remote attackers to establish sessions via a crafted message. This can be achieved by leveraging a signature-validation bypass for SAML messages containing unsigned elements, incorrect validation of XML messages, or a certificate-chain validation bypass for an XML signature element that contains the signing certificate.
Recommendations For versions 6.1.1, 6.2.0, 6.2.1, and 6.2.2, update to a version that includes the necessary security fixes to address the signature-validation bypass, incorrect XML validation, and certificate-chain validation bypass issues. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-3314

Affected Products

Ibm Tivoli Federated Identity Manager
Ibm Tivoli Federated Identity Manager Business Gateway