Cross-Site Scripting Vulnerabilities in IBM Tivoli Federated Identity Manager
CVE-2015-1966

Currently unrated

Key Information:

Vendor

IBM

Vendor
CVE Published:
4 July 2015

What is CVE-2015-1966?

IBM Tivoli Federated Identity Manager has multiple cross-site scripting vulnerabilities that could be exploited by remote attackers. By crafting a specially designed URL, attackers can inject arbitrary web scripts or HTML through specific macros (ERROR_DESCRIPTION and TOKEN:RelayState) in affected versions of the product. This flaw allows attackers to potentially manipulate user interactions and access sensitive information.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.