CVE-2008-7299

Severity
5.0MEDIUM
EPSS
0.2%
top 54.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 12
Latest updateMay 17

Description

IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2 uses an incomplete SAML 1.x browser-artifact, which allows remote OpenID providers to spoof assertions via vectors related to the Issuer field.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-x2wr-2x34-4hqr: IBM Tivoli Federated Identity Manager (TFIM) 62022-05-17
CVEList
CVE-2008-7299: IBM Tivoli Federated Identity Manager (TFIM) 62011-08-12
CVE-2008-7299 (MEDIUM CVSS 5) | IBM Tivoli Federated Identity Manag | cvebase.io