CVE-2011-1386: Medium severity ibm tivoli federated identity manager business gateway vulnerability
IBM Tivoli Federated Identity Manager (TFIM) and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.1.1, 6.2.0, and 6.2.1 do not properly handle signature validations based on SAML 1.0, 1.1, and 2.0, which allows remote attackers to bypass intended authentication or authorization requirements via a non-conforming SAML signature.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1386?
CVE-2011-1386 has a medium severity, enabling remote attackers to bypass authentication or authorization requirements.
How do I fix CVE-2011-1386?
To resolve CVE-2011-1386, users should upgrade to IBM Tivoli Federated Identity Manager versions 6.2.1 or later.
What software is affected by CVE-2011-1386?
CVE-2011-1386 affects IBM Tivoli Federated Identity Manager versions 6.1.1, 6.2.0, and 6.2.1, including the Business Gateway.
What are the implications of CVE-2011-1386?
Exploiting CVE-2011-1386 allows attackers to potentially gain unauthorized access to services or data.
Is CVE-2011-1386 exploitable remotely?
Yes, CVE-2011-1386 can be exploited remotely, posing a significant risk to systems using the affected IBM software.