CVE-2014-3097
https://notcve.org/view.php?id=CVE-2014-3097
Open redirect vulnerability in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0-TIV-TFIM-IF0015, 6.2.1 before 6.2.1-TIV-TFIM-IF0007, and 6.2.2 before 6.2.2-TIV-TFIM-IF0011 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. Vulnerabilidad de redirección abierta en IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 anterior a 6.2.0-TIV-TFIM-IF0015, 6.2.1 anterior a 6.2.1-TIV-TFIM-IF0007, y 6.2.2 anterior a 6.2.2-TIV-TFIM-IF0011 permite a atacantes remotos redirigir usuarios hacia sitios web arbitrarios y realizar ataques de phishing a través de vectores no especificados. • http://www-01.ibm.com/support/docview.wss?uid=swg1IV64324 http://www-01.ibm.com/support/docview.wss?uid=swg1IV64325 http://www-01.ibm.com/support/docview.wss?uid=swg1IV64349 http://www-01.ibm.com/support/docview.wss?uid=swg1IV64376 http://www-01.ibm.com/support/docview.wss? •
CVE-2014-0961
https://notcve.org/view.php?id=CVE-2014-0961
Cross-site request forgery (CSRF) vulnerability in IBM Tivoli Identity Manager (ITIM) 5.0 before 5.0.0.15 and 5.1 before 5.1.0.15 and IBM Security Identity Manager (ISIM) 6.0 before 6.0.0.2 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences. Vulnerabilidad de CSRF en IBM Tivoli Identity Manager (ITIM) 5.0 anterior a 5.0.0.15 y 5.1 anterior a 5.1.0.15 y IBM Security Identity Manager (ISIM) 6.0 anterior a 6.0.0.2 permite a usuarios remotos autenticados secuestrar la autenticación de usuarios arbitrarios para solicitudes que insertan secuencias de XSS. • http://secunia.com/advisories/59080 http://www-01.ibm.com/support/docview.wss?uid=swg21674754 http://www.securityfocus.com/bid/67909 https://exchange.xforce.ibmcloud.com/vulnerabilities/92747 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2013-5429
https://notcve.org/view.php?id=CVE-2013-5429
The Risk Based Access functionality in IBM Tivoli Federated Identity Manager (TFIM) 6.2.2 before FP9 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.2 before FP9 does not prevent reuse of One Time Password (OTP) tokens, which makes it easier for remote authenticated users to complete transactions by leveraging access to an already-used token. La funcionalidad de Acceso Basado en el Riesgo de IBM Tivoli Federated Identity Manager (TFIM) 6.2.2 antes de FP9 y Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.2 antes de FP9 no impide la reutilización de One Time Password (OTP) tokens, lo que hace más fácil para los usuarios remotos autenticados para completar las transacciones mediante el aprovechamiento de acceso a un símbolo usado ya. • http://www-01.ibm.com/support/docview.wss?uid=swg1IV52624 http://www-01.ibm.com/support/docview.wss?uid=swg21660509 http://www-01.ibm.com/support/docview.wss?uid=swg21660510 https://exchange.xforce.ibmcloud.com/vulnerabilities/87561 • CWE-287: Improper Authentication •
CVE-2013-5431
https://notcve.org/view.php?id=CVE-2013-5431
Open redirect vulnerability in IBM Tivoli Federated Identity Manager (TFIM) 6.1.1 before IF 15, 6.2.0 before IF 14, 6.2.1, and 6.2.2 before IF 8 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.1.1 before IF 15, 6.2.0 before IF 14, 6.2.1, and 6.2.2 before IF 8 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. Vulnerablilidad de redirección abierta en en IBM Tivoli Federated Identity Manager (TFIM) 6.1.1 anterior a IF 15, 6.2.0 anterior a IF 14, 6.2.1 y 6.2.2 anterior a IF 8 y Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.1.1 anterior a IF 15, 6.2.0 anterior a IF 14, 6.2.1 y 6.2.2 antes de IF 8 permite a atacantes remotos redirigir a los usuarios a sitios web arbitrarios y llevar a cabo ataques de phishing a través de vectores no especificados. • http://www-01.ibm.com/support/docview.wss?uid=swg1IV50639 http://www-01.ibm.com/support/docview.wss?uid=swg21654114 http://www.kb.cert.org/vuls/id/596990 https://exchange.xforce.ibmcloud.com/vulnerabilities/87616 • CWE-20: Improper Input Validation •
CVE-2013-0582
https://notcve.org/view.php?id=CVE-2013-0582
Cross-site scripting (XSS) vulnerability in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.12, 6.2.1 before 6.2.1.5, and 6.2.2 before 6.2.2.4 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.0 before 6.2.0.12 and 6.2.1 before 6.2.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL that triggers a SAML 2.0 response. Vulnerabilidad de ejecución de comandos en sitios cruzados (XSS) en IBM Tivoli Federated Identity Manager (TFIM) v6.2.0 antes de v6.2.0.12, v6.2.1 antes de v6.2.1.5, y v6.2.2 antes de v6.2.2.4 y Tivoli Federated Identity Manager Business Gateway (TFIMBG) v6.2.0 antes de v6.2.0.12 y v6.2.1 antes de v6.2.1.5 permite a atacantes remotos inyectar HTML o secuencias de comandos weba través de una URL debidamente modificada que dispara una respuesta SAML v2.0 • http://www-01.ibm.com/support/docview.wss?uid=swg1IV26033 http://www-01.ibm.com/support/docview.wss?uid=swg1IV26034 http://www-01.ibm.com/support/docview.wss?uid=swg1IV31640 http://www-01.ibm.com/support/docview.wss?uid=swg21635688 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •