Security Advisory

CVE-2008-7299

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2011-08-12 17:00:00
Last updated 2024-09-16 22:50:46
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2 uses an incomplete SAML 1.x browser-artifact, which allows remote OpenID providers to spoof assertions via vectors related to the Issuer field.