CVE-2015-1966: XSS
Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before FP17, 6.2.1 before FP9, and 6.2.2 before FP15, as used in Security Access Manager for Mobile and other products, allow remote attackers to inject arbitrary web script or HTML via a crafted URL, related to the (1) ERRORDESCRIPTION and (2) TOKEN:RelayState macros.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1966?
CVE-2015-1966 has a severity rating that allows remote attackers to exploit multiple cross-site scripting vulnerabilities.
How do I fix CVE-2015-1966?
To fix CVE-2015-1966, upgrade to IBM Tivoli Federated Identity Manager versions 6.2.0 FP17, 6.2.1 FP9, or 6.2.2 FP15 or later.
What products are affected by CVE-2015-1966?
CVE-2015-1966 affects IBM Tivoli Federated Identity Manager versions 6.2.0, 6.2.1, and 6.2.2 before specified fix packs.
Can CVE-2015-1966 lead to data breaches?
Yes, CVE-2015-1966 can potentially lead to data breaches through remote code execution via cross-site scripting.
Is there a workaround for CVE-2015-1966 if I can't upgrade?
There are no specific workarounds for CVE-2015-1966, so upgrading to the safe versions is strongly recommended.