5
CVSSv2

CVE-2008-7299

Published: 12/08/2011 Updated: 12/08/2011
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 prior to 6.2.0.2 uses an incomplete SAML 1.x browser-artifact, which allows remote OpenID providers to spoof assertions via vectors related to the Issuer field.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm tivoli federated identity manager 6.2.0

ibm tivoli federated identity manager 6.2.0.1