IBM Tivoli Federated Identity Manager Business Gateway Security Bypass Vulnerability
BID:64999
Info
IBM Tivoli Federated Identity Manager Business Gateway Security Bypass Vulnerability
| Bugtraq ID: | 64999 |
| Class: | Access Validation Error |
| CVE: |
CVE-2013-5429 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 31 2013 12:00AM |
| Updated: | Jan 22 2014 01:02AM |
| Credit: | IBM |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
IBM Tivoli Federated Identity Manager Business Gateway Security Bypass Vulnerability
IBM Tivoli Federated Identity Manager Business Gateway is prone to a security-bypass vulnerability.
Attackers can exploit this issue to bypass certain security restrictions and perform unauthorized actions on the affected application. This may aid in further attacks.
IBM Tivoli Federated Identity Manager Business Gateway 6.2.2 is vulnerable; other versions may also be affected.
IBM Tivoli Federated Identity Manager Business Gateway is prone to a security-bypass vulnerability.
Attackers can exploit this issue to bypass certain security restrictions and perform unauthorized actions on the affected application. This may aid in further attacks.
IBM Tivoli Federated Identity Manager Business Gateway 6.2.2 is vulnerable; other versions may also be affected.
Exploit / POC
IBM Tivoli Federated Identity Manager Business Gateway Security Bypass Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
IBM Tivoli Federated Identity Manager Business Gateway Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
IBM Tivoli Federated Identity Manager Business Gateway Security Bypass Vulnerability
References:
References:
- IBM Homepage (IBM)