CVE-2011-3138
published 2011-08-12CVE-2011-3138: The LTPA STS module support implementation in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.9 and Tivoli Federated Identity Manager Business…
PriorityP424medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
1.76%
75.6th percentile
The LTPA STS module support implementation in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.9 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.0 before 6.2.0.9 relies on a static instance of a Java Development Kit (JDK) class, which might allow attackers to bypass LTPA token signature verification by leveraging lack of thread safety.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | tivoli_federated_identity_manager | — | — |
| ibm | tivoli_federated_identity_manager | — | — |
| ibm | tivoli_federated_identity_manager | — | — |
| ibm | tivoli_federated_identity_manager | — | — |
| ibm | tivoli_federated_identity_manager | — | — |
| ibm | tivoli_federated_identity_manager_business_gateway | — | — |
| ibm | tivoli_federated_identity_manager_business_gateway | — | — |
| ibm | tivoli_federated_identity_manager_business_gateway | — | — |
| ibm | tivoli_federated_identity_manager_business_gateway | — | — |
| ibm | tivoli_federated_identity_manager_business_gateway | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www-01.ibm.com/support/docview.wss?uid=swg1IV01318http://www.ibm.com/support/docview.wss?uid=swg24029497http://www.ibm.com/support/docview.wss?uid=swg24029498https://exchange.xforce.ibmcloud.com/vulnerabilities/69198http://www-01.ibm.com/support/docview.wss?uid=swg1IV01318http://www.ibm.com/support/docview.wss?uid=swg24029497http://www.ibm.com/support/docview.wss?uid=swg24029498https://exchange.xforce.ibmcloud.com/vulnerabilities/69198
2011-08-12
Published