[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256288

 
 

909

 
 

199146

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2011-3138Date: (C)2011-08-12   (M)2023-12-22


The LTPA STS module support implementation in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.9 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.0 before 6.2.0.9 relies on a static instance of a Java Development Kit (JDK) class, which might allow attackers to bypass LTPA token signature verification by leveraging lack of thread safety.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.0
Exploit Score: 10.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: NONE
Integrity: PARTIAL
Availability: NONE
  
Reference:
IV01318
http://www.ibm.com/support/docview.wss?uid=swg24029497
http://www.ibm.com/support/docview.wss?uid=swg24029498
ibm-tfim-security-bypass(69198)

CPE    10
cpe:/a:ibm:tivoli_federated_identity_manager:6.2.0.2
cpe:/a:ibm:tivoli_federated_identity_manager:6.2.0.1
cpe:/a:ibm:tivoli_federated_identity_manager_business_gateway:6.2.0
cpe:/a:ibm:tivoli_federated_identity_manager_business_gateway:6.2.0.3
...

© SecPod Technologies