Page 5 of 34 results (0.005 seconds)

CVSS: 2.6EPSS: 0%CPEs: 2EXPL: 0

IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2, when configured as an OpenID provider, does not delete the site information cookie in response to a user's deletion of a relying-party trust entry, which allows user-assisted remote attackers to bypass intended trust restrictions via vectors that trigger absence of the consent-to-authenticate page. IBM Tivoli Federated Identity Manager (TFIM) v6.2.0 anterior a v6.2.0.2, cuando se configura como un proveedor de OpenID, no borra la cookie de información en respuesta a la eliminacion de un usuario de una entidad de confianza, lo que permite que un atacante eluda las restricciones de confianza mediante vectores que producen la falta de autenticación de la página • http://www-01.ibm.com/support/docview.wss?uid=swg1IZ44555 http://www.ibm.com/support/docview.wss?uid=swg24029497 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 10.0EPSS: 0%CPEs: 10EXPL: 0

Unspecified vulnerability in the Management Console in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.9 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.0 before 6.2.0.9 has unknown impact and attack vectors, aka APAR IV03048. Vulnerabilidad no especificada en la consola de administración de IBM Tivoli Federated Identity Manager (TFIM) v6.2.0 anterior v6.2.0.9 y Tivoli Federated Identity Business Gateway Manager (TFIMBG) v6.2.0 anterior a v6.2.0.9 tiene un impacto y un vector de ataque desconocido, también conocido como APAR IV03048. • http://secunia.com/advisories/45555 http://www-01.ibm.com/support/docview.wss?uid=swg1IV03048 http://www.ibm.com/support/docview.wss?uid=swg24029497 http://www.ibm.com/support/docview.wss?uid=swg24029498 •

CVSS: 5.0EPSS: 0%CPEs: 2EXPL: 0

IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2 uses an incomplete SAML 1.x browser-artifact, which allows remote OpenID providers to spoof assertions via vectors related to the Issuer field. IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 anterior a v6.2.0.2 utiliza un avegador artefacto (browser-artifact) SAML 1.x, que permite a los proveedores de OpenID falsificar aserciones mediante vectores relacionados con el campo Issuer • http://www-01.ibm.com/support/docview.wss?uid=swg1IZ35742 http://www.ibm.com/support/docview.wss?uid=swg24029497 • CWE-20: Improper Input Validation •

CVSS: 10.0EPSS: 0%CPEs: 10EXPL: 0

Unspecified vulnerability in the Management Console in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.9 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.0 before 6.2.0.9 has unknown impact and attack vectors, aka APAR IV03050. Vulnerabilidad no especificada en Management Console en IBM Tivoli Federated Identity Manager (TFIM) v6.2.0 anterior a v6.2.0.9 y Tivoli Federated Identity Manager Business Gateway (TFIMBG) v6.2.0 anterior a v6.2.0.9 tiene un impacto desconocido y vectores de ataque, también conocido como APAR IV03050. • http://secunia.com/advisories/45555 http://www-01.ibm.com/support/docview.wss?uid=swg1IV03050 http://www.ibm.com/support/docview.wss?uid=swg24029497 http://www.ibm.com/support/docview.wss?uid=swg24029498 https://exchange.xforce.ibmcloud.com/vulnerabilities/69203 https://exchange.xforce.ibmcloud.com/vulnerabilities/69204 •

CVSS: 10.0EPSS: 0%CPEs: 10EXPL: 0

Unspecified vulnerability in the Runtime in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.9 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.0 before 6.2.0.9 has unknown impact and attack vectors. Vulnerabilidad no especificada en el Runtime en IBM Tivoli Federated Identity Manager (TFIM) v6.2.0 anterior a v6.2.0.9 y Tivoli Federated Identity Manager Business Gateway (TFIMBG) v6.2.0 anterior a v6.2.0.9 tiene un impacto desconocido y vectores de ataque. • http://secunia.com/advisories/45555 http://www-01.ibm.com/support/docview.wss?uid=swg1IV03074 http://www.ibm.com/support/docview.wss?uid=swg24029497 http://www.ibm.com/support/docview.wss?uid=swg24029498 https://exchange.xforce.ibmcloud.com/vulnerabilities/69205 •