- Description
- An XML parsing vulnerability affects IBM SAML-based single sign-on (SSO) systems (IBM Security Access Manager 9.0.0 - 9.0.4 and IBM Tivoli Federated Identity Manager 6.2 - 6.0.2.) This vulnerability can allow an attacker with authenticated access to trick SAML systems into authenticating as a different user without knowledge of the victim users password. IBM X-Force ID: 139754.
- Source
- psirt@us.ibm.com
- NVD status
- Modified
CVSS 3.0
- Type
- Primary
- Base score
- 5.9
- Impact score
- 3.4
- Exploitability score
- 2.5
- Vector string
- CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Severity
- MEDIUM
CVSS 2.0
- Type
- Primary
- Base score
- 4.6
- Impact score
- 6.4
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:P/I:P/A:P
- nvd@nist.gov
- CWE-287
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ibm:security_access_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "706535A6-BE47-4AFA-BB65-00B72043D1A3",
"versionEndIncluding": "9.0.4",
"versionStartIncluding": "9.0.0"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ibm:tivoli_federated_identity_manager:6.2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E508843E-DEA8-433D-AFD5-2730D2745E0B"
},
{
"criteria": "cpe:2.3:a:ibm:tivoli_federated_identity_manager:6.2.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F674F64E-F51F-4F5E-AFCD-952958E66FE2"
},
{
"criteria": "cpe:2.3:a:ibm:tivoli_federated_identity_manager:6.2.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "93F48368-9617-4EE6-BF7A-6873229C0D66"
}
],
"operator": "OR"
}
]
}
]