OpenID Trust Bypass Vulnerability in IBM Tivoli Federated Identity Manager
CVE-2009-5085
Currently unrated
What is CVE-2009-5085?
IBM Tivoli Federated Identity Manager (TFIM) version 6.2.0 before 6.2.0.2 has a vulnerability when configured as an OpenID provider. It fails to delete the site information cookie upon a user removing a relying-party trust entry. This oversight allows remote attackers, with user assistance, to bypass trust restrictions intended to secure the authentication process, potentially exposing sensitive user data and credentials.