CVE-2011-3138

The LTPA STS module support implementation in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.9 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.0 before 6.2.0.9 relies on a static instance of a Java Development Kit (JDK) class, which might allow attackers to bypass LTPA token signature verification by leveraging lack of thread safety.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 46%
VendorProductVersion
ibmtivoli_federated_identity_manager
6.2.0
ibmtivoli_federated_identity_manager
6.2.0.1
ibmtivoli_federated_identity_manager
6.2.0.2
ibmtivoli_federated_identity_manager
6.2.0.3
ibmtivoli_federated_identity_manager
6.2.0.8
ibmtivoli_federated_identity_manager_business_gateway
6.2.0
ibmtivoli_federated_identity_manager_business_gateway
6.2.0.1
ibmtivoli_federated_identity_manager_business_gateway
6.2.0.2
ibmtivoli_federated_identity_manager_business_gateway
6.2.0.3
ibmtivoli_federated_identity_manager_business_gateway
6.2.0.8
𝑥
= Vulnerable software versions