CVE-2009-5085
IBM Tivoli Federated Identity Manager 6.2.0 - Trust Restriction Bypass via OpenID Provider Cookie Handling
Title source: llmDescription
IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2, when configured as an OpenID provider, does not delete the site information cookie in response to a user's deletion of a relying-party trust entry, which allows user-assisted remote attackers to bypass intended trust restrictions via vectors that trigger absence of the consent-to-authenticate page.
References (2)
Core 2
Core References
Patch vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IZ44555
Various Sources x_refsource_confirm
http://www.ibm.com/support/docview.wss?uid=swg24029497
Scores
EPSS
0.0112
EPSS Percentile
62.9%
Details
CWE
CWE-264
Status
published
Products (2)
ibm/tivoli_federated_identity_manager
6.2.0
ibm/tivoli_federated_identity_manager
6.2.0.1
Published
Aug 12, 2011
Tracked Since
Feb 18, 2026