CVE-2009-5083

IBM Tivoli Federated Identity Manager - Authentication Bypass

Title source: rule

Description

IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2, when configured as an OpenID relying party, does not perform the expected login rejection upon receiving an OP-Identifier from an OpenID provider, which allows remote attackers to bypass authentication via unspecified vectors.

Scores

EPSS 0.0022
EPSS Percentile 43.9%

Classification

CWE
CWE-287
Status draft

Affected Products (2)

ibm/tivoli_federated_identity_manager
ibm/tivoli_federated_identity_manager

Timeline

Published Aug 12, 2011
Tracked Since Feb 18, 2026