Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
IBM Tivoli Federated Identity Manager (TFIM) and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.1.1, 6.2.0, 6.2.1, and 6.2.2 allow remote attackers to establish sessions via a crafted message that leverages (1) a signature-validation bypass for SAML messages containing unsigned elements, (2) incorrect validation of XML messages, or (3) a certificate-chain validation bypass for an XML signature element that contains the signing certificate.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
IBM TFIM/TFIMBG 输入验证漏洞
Vulnerability Description
IBM Tivoli Federated Identity Manager(TFIM)是美国IBM公司的一款跨企业的联邦身份管理产品。该产品向使用多种应用程序的用户提供Web和联合单点登录功能(SSO)。 IBM Tivoli Federated Identity Manager (TFIM)和Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.1.1、6.2.0、6.2.1和6.2.2版本中存在漏洞。远程攻击者可利用该漏洞建立会话,
CVSS Information
N/A
Vulnerability Type
N/A