IBM Tivoli Federated Identity Manager Vulnerability in OpenID Configuration
CVE-2009-5083
Currently unrated
Summary
IBM Tivoli Federated Identity Manager version 6.2.0 prior to 6.2.0.2, configured as an OpenID relying party, fails to reject invalid logins when it receives an OP-Identifier from an OpenID provider. This flaw allows remote attackers to exploit the authentication process, leading to unauthorized access to sensitive resources.
References
Timeline
Vulnerability Reserved
Vulnerability published