Vulnerability Name: | CVE-2011-1386 (CCN-71686) | ||||||||
Assigned: | 2011-12-07 | ||||||||
Published: | 2011-12-07 | ||||||||
Updated: | 2017-08-17 | ||||||||
Summary: | IBM Tivoli Federated Identity Manager (TFIM) and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.1.1, 6.2.0, and 6.2.1 do not properly handle signature validations based on SAML 1.0, 1.1, and 2.0, which allows remote attackers to bypass intended authentication or authorization requirements via a non-conforming SAML signature. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Other | ||||||||
References: | Source: MITRE Type: CNA CVE-2011-1386 Source: CCN Type: SA47218 IBM Tivoli Federated Identity Manager SAML Signature Validation Security Bypass Source: AIXAPAR Type: Patch, Vendor Advisory IV10793 Source: AIXAPAR Type: UNKNOWN IV10801 Source: AIXAPAR Type: UNKNOWN IV10813 Source: CCN Type: IBM Support & downloads IBM Tivoli Federated Identity Manager SAML (Security Assertion Markup Language) non-conformance vulnerability (CVE-2011-1386) * * * * * * Source: CONFIRM Type: Patch, Vendor Advisory http://www.ibm.com/support/docview.wss?uid=swg21575309 Source: CCN Type: OSVDB ID: 77687 IBM Tivoli Federated Identity Manager SAML Signature Validation Bypass Source: CCN Type: BID-51064 IBM Tivoli Federated Identity Manager SAML Signature Validation Security Bypass Vulnerability Source: XF Type: UNKNOWN tfim-saml-weak-security(71686) Source: XF Type: UNKNOWN tfim-saml-weak-security(71686) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |