2.6
CVSSv2

CVE-2009-5085

Published: 12/08/2011 Updated: 25/04/2012
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 prior to 6.2.0.2, when configured as an OpenID provider, does not delete the site information cookie in response to a user's deletion of a relying-party trust entry, which allows user-assisted remote malicious users to bypass intended trust restrictions via vectors that trigger absence of the consent-to-authenticate page.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm tivoli federated identity manager 6.2.0

ibm tivoli federated identity manager 6.2.0.1