CVE-2012-6359
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.11, 6.2.1 before 6.2.1.3, and 6.2.2 before 6.2.2.2 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.0 before 6.2.0.11, 6.2.1 before 6.2.1.3, and 6.2.2 before 6.2.2.2 do not check whether an OpenID attribute is signed in the (1) SREG (aka simple registration extension) and (2) AX (aka attribute exchange extension) cases, which allows man-in-the-middle attackers to spoof OpenID provider data by inserting unsigned attributes.
IBM Tivoli Federated Identity Manager (TFIM) v6.2.0 antes de v6.2.0.11, v6.2.1 antes de v6.2.1.3 y v6.2.2 antes de v6.2.2.2 y Tivoli Federated Identity Manager Business Gateway (TFIMBG) v6.2.0 antes de v6.2.0.11, v6.2.1 antes de v6.2.1.3 y v6.2.2 antes de v6.2.2.2 no comprueban si un atributo OpenID está firmado en el (1) SREG (extensión registro simple) y (2) casos de extensión AX (también conocido como extensión de intercambio de atributos), que permite a atacantes de man-in-the-middle, falsificar los datos del proveedor de OpenID mediante la inserción de atributos no firmados.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-12-16 CVE Reserved
- 2013-01-18 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/51212 | Third Party Advisory | |
http://www.securityfocus.com/bid/56390 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/77790 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg1IV23451 | 2017-08-29 | |
http://www-01.ibm.com/support/docview.wss?uid=swg1IV23452 | 2017-08-29 | |
http://www-01.ibm.com/support/docview.wss?uid=swg1IV23453 | 2017-08-29 | |
http://www-01.ibm.com/support/docview.wss?uid=swg21615744 | 2017-08-29 | |
http://www-01.ibm.com/support/docview.wss?uid=swg21615748 | 2017-08-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ibm Search vendor "Ibm" | Tivoli Federated Identity Manager Search vendor "Ibm" for product "Tivoli Federated Identity Manager" | 6.2.0 Search vendor "Ibm" for product "Tivoli Federated Identity Manager" and version "6.2.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Tivoli Federated Identity Manager Search vendor "Ibm" for product "Tivoli Federated Identity Manager" | 6.2.0.1 Search vendor "Ibm" for product "Tivoli Federated Identity Manager" and version "6.2.0.1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Tivoli Federated Identity Manager Search vendor "Ibm" for product "Tivoli Federated Identity Manager" | 6.2.0.2 Search vendor "Ibm" for product "Tivoli Federated Identity Manager" and version "6.2.0.2" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Tivoli Federated Identity Manager Search vendor "Ibm" for product "Tivoli Federated Identity Manager" | 6.2.0.3 Search vendor "Ibm" for product "Tivoli Federated Identity Manager" and version "6.2.0.3" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Tivoli Federated Identity Manager Search vendor "Ibm" for product "Tivoli Federated Identity Manager" | 6.2.0.8 Search vendor "Ibm" for product "Tivoli Federated Identity Manager" and version "6.2.0.8" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Tivoli Federated Identity Manager Search vendor "Ibm" for product "Tivoli Federated Identity Manager" | 6.2.0.9 Search vendor "Ibm" for product "Tivoli Federated Identity Manager" and version "6.2.0.9" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Tivoli Federated Identity Manager Search vendor "Ibm" for product "Tivoli Federated Identity Manager" | 6.2.0.10 Search vendor "Ibm" for product "Tivoli Federated Identity Manager" and version "6.2.0.10" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Tivoli Federated Identity Manager Search vendor "Ibm" for product "Tivoli Federated Identity Manager" | 6.2.1 Search vendor "Ibm" for product "Tivoli Federated Identity Manager" and version "6.2.1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Tivoli Federated Identity Manager Search vendor "Ibm" for product "Tivoli Federated Identity Manager" | 6.2.1.1 Search vendor "Ibm" for product "Tivoli Federated Identity Manager" and version "6.2.1.1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Tivoli Federated Identity Manager Search vendor "Ibm" for product "Tivoli Federated Identity Manager" | 6.2.1.2 Search vendor "Ibm" for product "Tivoli Federated Identity Manager" and version "6.2.1.2" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Tivoli Federated Identity Manager Search vendor "Ibm" for product "Tivoli Federated Identity Manager" | 6.2.2 Search vendor "Ibm" for product "Tivoli Federated Identity Manager" and version "6.2.2" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Tivoli Federated Identity Manager Business Gateway Search vendor "Ibm" for product "Tivoli Federated Identity Manager Business Gateway" | 6.2.0 Search vendor "Ibm" for product "Tivoli Federated Identity Manager Business Gateway" and version "6.2.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Tivoli Federated Identity Manager Business Gateway Search vendor "Ibm" for product "Tivoli Federated Identity Manager Business Gateway" | 6.2.0.1 Search vendor "Ibm" for product "Tivoli Federated Identity Manager Business Gateway" and version "6.2.0.1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Tivoli Federated Identity Manager Business Gateway Search vendor "Ibm" for product "Tivoli Federated Identity Manager Business Gateway" | 6.2.0.2 Search vendor "Ibm" for product "Tivoli Federated Identity Manager Business Gateway" and version "6.2.0.2" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Tivoli Federated Identity Manager Business Gateway Search vendor "Ibm" for product "Tivoli Federated Identity Manager Business Gateway" | 6.2.0.3 Search vendor "Ibm" for product "Tivoli Federated Identity Manager Business Gateway" and version "6.2.0.3" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Tivoli Federated Identity Manager Business Gateway Search vendor "Ibm" for product "Tivoli Federated Identity Manager Business Gateway" | 6.2.0.8 Search vendor "Ibm" for product "Tivoli Federated Identity Manager Business Gateway" and version "6.2.0.8" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Tivoli Federated Identity Manager Business Gateway Search vendor "Ibm" for product "Tivoli Federated Identity Manager Business Gateway" | 6.2.0.9 Search vendor "Ibm" for product "Tivoli Federated Identity Manager Business Gateway" and version "6.2.0.9" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Tivoli Federated Identity Manager Business Gateway Search vendor "Ibm" for product "Tivoli Federated Identity Manager Business Gateway" | 6.2.0.10 Search vendor "Ibm" for product "Tivoli Federated Identity Manager Business Gateway" and version "6.2.0.10" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Tivoli Federated Identity Manager Business Gateway Search vendor "Ibm" for product "Tivoli Federated Identity Manager Business Gateway" | 6.2.1 Search vendor "Ibm" for product "Tivoli Federated Identity Manager Business Gateway" and version "6.2.1" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Tivoli Federated Identity Manager Business Gateway Search vendor "Ibm" for product "Tivoli Federated Identity Manager Business Gateway" | 6.2.2 Search vendor "Ibm" for product "Tivoli Federated Identity Manager Business Gateway" and version "6.2.2" | - |
Affected
|