Page 3 of 12 results (0.017 seconds)

CVSS: 5.8EPSS: 0%CPEs: 8EXPL: 0

IBM Tivoli Federated Identity Manager (TFIM) and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.1.1, 6.2.0, 6.2.1, and 6.2.2 allow remote attackers to establish sessions via a crafted message that leverages (1) a signature-validation bypass for SAML messages containing unsigned elements, (2) incorrect validation of XML messages, or (3) a certificate-chain validation bypass for an XML signature element that contains the signing certificate. IBM Tivoli Federated Identity Manager (TFIM) y Tivoli Federated Identity Manager Business Gateway (TFIMBG) v6.1.1, v6.2.0, v6.2.1, y v6.2.2 permite atacantes remotos establecer sesiones a través de un mensaje que aprovecha (1) para evitar una validación de firma que para mensajes SAML que contienen elementos no firmados, (2) validación incorrecta de mensajes XML, o (3) evitar la validación de una cadena de certificados de un elemento XML firmado que contiene la firma del certificado. • http://www-01.ibm.com/support/docview.wss?uid=swg1IV23435 http://www-01.ibm.com/support/docview.wss?uid=swg1IV23442 http://www-01.ibm.com/support/docview.wss?uid=swg1IV23445 http://www-01.ibm.com/support/docview.wss?uid=swg1IV23448 http://www-01.ibm.com/support/docview.wss? • CWE-20: Improper Input Validation •

CVSS: 4.3EPSS: 0%CPEs: 6EXPL: 0

IBM Tivoli Federated Identity Manager (TFIM) and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.1.1, 6.2.0, and 6.2.1 do not properly handle signature validations based on SAML 1.0, 1.1, and 2.0, which allows remote attackers to bypass intended authentication or authorization requirements via a non-conforming SAML signature. IBM Tivoli Federated Identity Manager (TFIM) y Tivoli Federated Identity Manager Business Gateway (TFIMBG) v6.1.1, v6.2.0, y v6.2.1, no manejan adecuadamente las validaciones de firmas basadas en SAML v1.0, v1.1, y v2.0, lo que permite a atacantes remotos evitar las restricciones de acceso o requisitos de autorización a través de una firma SAML no conforme. • http://www-01.ibm.com/support/docview.wss?uid=swg1IV10793 http://www-01.ibm.com/support/docview.wss?uid=swg1IV10801 http://www-01.ibm.com/support/docview.wss?uid=swg1IV10813 http://www.ibm.com/support/docview.wss?uid=swg21575309 https://exchange.xforce.ibmcloud.com/vulnerabilities/71686 • CWE-264: Permissions, Privileges, and Access Controls •