CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:L/Au:N/C:N/I:P/A:N
AI Score
Confidence
Low
EPSS
Percentile
55.0%
The LTPA STS module support implementation in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.9 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.0 before 6.2.0.9 relies on a static instance of a Java Development Kit (JDK) class, which might allow attackers to bypass LTPA token signature verification by leveraging lack of thread safety.
Vendor | Product | Version | CPE |
---|---|---|---|
ibm | tivoli_federated_identity_manager | 6.2.0 | cpe:2.3:a:ibm:tivoli_federated_identity_manager:6.2.0:*:*:*:*:*:*:* |
ibm | tivoli_federated_identity_manager | 6.2.0.1 | cpe:2.3:a:ibm:tivoli_federated_identity_manager:6.2.0.1:*:*:*:*:*:*:* |
ibm | tivoli_federated_identity_manager | 6.2.0.2 | cpe:2.3:a:ibm:tivoli_federated_identity_manager:6.2.0.2:*:*:*:*:*:*:* |
ibm | tivoli_federated_identity_manager | 6.2.0.3 | cpe:2.3:a:ibm:tivoli_federated_identity_manager:6.2.0.3:*:*:*:*:*:*:* |
ibm | tivoli_federated_identity_manager | 6.2.0.8 | cpe:2.3:a:ibm:tivoli_federated_identity_manager:6.2.0.8:*:*:*:*:*:*:* |
ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0 | cpe:2.3:a:ibm:tivoli_federated_identity_manager_business_gateway:6.2.0:*:*:*:*:*:*:* |
ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0.1 | cpe:2.3:a:ibm:tivoli_federated_identity_manager_business_gateway:6.2.0.1:*:*:*:*:*:*:* |
ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0.2 | cpe:2.3:a:ibm:tivoli_federated_identity_manager_business_gateway:6.2.0.2:*:*:*:*:*:*:* |
ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0.3 | cpe:2.3:a:ibm:tivoli_federated_identity_manager_business_gateway:6.2.0.3:*:*:*:*:*:*:* |
ibm | tivoli_federated_identity_manager_business_gateway | 6.2.0.8 | cpe:2.3:a:ibm:tivoli_federated_identity_manager_business_gateway:6.2.0.8:*:*:*:*:*:*:* |