CVE Database
/

CVE-2011-1386

Back to search

CVE-2011-1386

Published: Jan 4, 2012

Modified: Aug 6, 2024

PUBLISHED

Description

IBM Tivoli Federated Identity Manager (TFIM) and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.1.1, 6.2.0, and 6.2.1 do not properly handle signature validations based on SAML 1.0, 1.1, and 2.0, which allows remote attackers to bypass intended authentication or authorization requirements via a non-conforming SAML signature.

VendorProductVersions

n/a

n/a

affected
n/a

References

IV10813
vendor-advisory
x_refsource_AIXAPAR
tfim-saml-weak-security(71686)
vdb-entry
x_refsource_XF
IV10793
vendor-advisory
x_refsource_AIXAPAR
IV10801
vendor-advisory
x_refsource_AIXAPAR

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now