OpenID Trust Bypass Vulnerability in IBM Tivoli Federated Identity Manager
CVE-2009-5085

Currently unrated

Key Information:

Vendor
IBM
Vendor
CVE Published:
12 August 2011

Summary

IBM Tivoli Federated Identity Manager (TFIM) version 6.2.0 before 6.2.0.2 has a vulnerability when configured as an OpenID provider. It fails to delete the site information cookie upon a user removing a relying-party trust entry. This oversight allows remote attackers, with user assistance, to bypass trust restrictions intended to secure the authentication process, potentially exposing sensitive user data and credentials.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.