IBM Tivoli Federated Identity Manager Vulnerability in OpenID Configuration
CVE-2009-5083

Currently unrated

Key Information:

Vendor
IBM
Vendor
CVE Published:
12 August 2011

Summary

IBM Tivoli Federated Identity Manager version 6.2.0 prior to 6.2.0.2, configured as an OpenID relying party, fails to reject invalid logins when it receives an OP-Identifier from an OpenID provider. This flaw allows remote attackers to exploit the authentication process, leading to unauthorized access to sensitive resources.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.