CVE-2008-7299: Input Validation
Published Aug 12, 2011
·Updated
IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2 uses an incomplete SAML 1.x browser-artifact, which allows remote OpenID providers to spoof assertions via vectors related to the Issuer field.
Affected Software
2 affected components
IBM Tivoli Federated Identity Manager=6.2.0
IBM Tivoli Federated Identity Manager=6.2.0.1
Event History
Aug 12, 2011
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-7299?
CVE-2008-7299 is considered a moderate severity vulnerability as it allows remote OpenID providers to spoof assertions.
2
How do I fix CVE-2008-7299?
To fix CVE-2008-7299, upgrade IBM Tivoli Federated Identity Manager to version 6.2.0.2 or later.
3
What versions are affected by CVE-2008-7299?
CVE-2008-7299 affects IBM Tivoli Federated Identity Manager versions 6.2.0 and 6.2.0.1.
4
What type of attack can be executed due to CVE-2008-7299?
CVE-2008-7299 can be exploited to spoof assertions by leveraging an incomplete SAML 1.x browser-artifact.
5
Who can exploit CVE-2008-7299?
Any remote OpenID provider can exploit CVE-2008-7299 if they are able to manipulate the Issuer field of the assertions.