CVE Database
/

CVE-2015-1966

Back to search

CVE-2015-1966

Published: Jul 4, 2015

Modified: Aug 6, 2024

PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before FP17, 6.2.1 before FP9, and 6.2.2 before FP15, as used in Security Access Manager for Mobile and other products, allow remote attackers to inject arbitrary web script or HTML via a crafted URL, related to the (1) ERROR_DESCRIPTION and (2) TOKEN:RelayState macros.

VendorProductVersions

n/a

n/a

affected
n/a

References

IV74198
vendor-advisory
x_refsource_AIXAPAR
IV74199
vendor-advisory
x_refsource_AIXAPAR
75537
vdb-entry
x_refsource_BID
IV74200
vendor-advisory
x_refsource_AIXAPAR
1032767
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now