CVE Database
/

CVE-2008-7299

Back to search

CVE-2008-7299

Published: Aug 12, 2011

Modified: Sep 16, 2024

PUBLISHED

Description

IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2 uses an incomplete SAML 1.x browser-artifact, which allows remote OpenID providers to spoof assertions via vectors related to the Issuer field.

VendorProductVersions

n/a

n/a

affected
n/a

References

IZ35742
vendor-advisory
x_refsource_AIXAPAR

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now