CVE Database
/

CVE-2012-6359

Back to search

CVE-2012-6359

Published: Jan 18, 2013

Modified: Aug 6, 2024

PUBLISHED

Description

IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.11, 6.2.1 before 6.2.1.3, and 6.2.2 before 6.2.2.2 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.0 before 6.2.0.11, 6.2.1 before 6.2.1.3, and 6.2.2 before 6.2.2.2 do not check whether an OpenID attribute is signed in the (1) SREG (aka simple registration extension) and (2) AX (aka attribute exchange extension) cases, which allows man-in-the-middle attackers to spoof OpenID provider data by inserting unsigned attributes.

VendorProductVersions

n/a

n/a

affected
n/a

References

tfim-openid-weak-security(77790)
vdb-entry
x_refsource_XF
51212
third-party-advisory
x_refsource_SECUNIA
IV23452
vendor-advisory
x_refsource_AIXAPAR
IV23453
vendor-advisory
x_refsource_AIXAPAR
56390
vdb-entry
x_refsource_BID
IV23451
vendor-advisory
x_refsource_AIXAPAR

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now