BM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.11, 6.2.1 before 6.2.1.3, and 6.2.2 before 6.2.2.2 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.0 before 6.2.0.11, 6.2.1 before 6.2.1.3, and 6.2.2 before 6.2.2.2 do not check whether an OpenID attribute is signed in the (1) SREG (aka simple registration extension) and (2) AX (aka attribute exchange extension) cases, which allows man-in-the-middle attackers to spoof OpenID provider data by inserting unsigned attributes.
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Configuration 6 (hide)
|
21 Nov 2024, 01:46
| Type | Values Removed | Values Added |
|---|---|---|
| References | () http://secunia.com/advisories/51212 - | |
| References | () http://www-01.ibm.com/support/docview.wss?uid=swg1IV23451 - | |
| References | () http://www-01.ibm.com/support/docview.wss?uid=swg1IV23452 - | |
| References | () http://www-01.ibm.com/support/docview.wss?uid=swg1IV23453 - | |
| References | () http://www-01.ibm.com/support/docview.wss?uid=swg21615744 - Vendor Advisory | |
| References | () http://www-01.ibm.com/support/docview.wss?uid=swg21615748 - Vendor Advisory | |
| References | () http://www.securityfocus.com/bid/56390 - | |
| References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/77790 - |
Published : 2013-01-18 21:55
Updated : 2025-04-11 00:51
NVD link : CVE-2012-6359
Mitre link : CVE-2012-6359
CVE.ORG link : CVE-2012-6359
JSON object : View
Permissions, Privileges, and Access Controls