CVE-2012-3315: Medium severity ibm tivoli federated identity manager business gateway vulnerability
The Java servlets in the management console in IBM Tivoli Federated Identity Manager (TFIM) through 6.2.2 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) before 6.2.2 do not require authentication for all resource downloads, which allows remote attackers to bypass intended J2EE security constraints, and obtain sensitive information related to (1) federation metadata or (2) a web plugin configuration template, via a crafted request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3315?
CVE-2012-3315 is categorized as a medium severity vulnerability due to its potential to allow unauthorized access.
How do I fix CVE-2012-3315?
To fix CVE-2012-3315, upgrade to IBM Tivoli Federated Identity Manager version 6.2.2 or later.
What software is affected by CVE-2012-3315?
CVE-2012-3315 affects IBM Tivoli Federated Identity Manager versions through 6.2.2 and various versions of Tivoli Federated Identity Manager Business Gateway.
Can CVE-2012-3315 be exploited remotely?
Yes, CVE-2012-3315 can be exploited remotely by attackers due to the lack of authentication for resource downloads.
What type of vulnerability is CVE-2012-3315?
CVE-2012-3315 is an authentication bypass vulnerability in Java servlets.