OpenID Trust Bypass Vulnerability in IBM Tivoli Federated Identity Manager
CVE-2009-5085
Currently unrated
Summary
IBM Tivoli Federated Identity Manager (TFIM) version 6.2.0 before 6.2.0.2 has a vulnerability when configured as an OpenID provider. It fails to delete the site information cookie upon a user removing a relying-party trust entry. This oversight allows remote attackers, with user assistance, to bypass trust restrictions intended to secure the authentication process, potentially exposing sensitive user data and credentials.
References
Timeline
Vulnerability Reserved
Vulnerability published