Open Redirection In IBM Tivoli Federated Identity Manager Vulnerabilities
17 Mar. 2015
Open redirect vulnerability in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0-TIV-TFIM-IF0015, 6.2.1 before 6.2.1-TIV-TFIM-IF0007, and 6.2.2 before 6.2.2-TIV-TFIM-IF0011 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks
* IBM Tivoli Federated Identity Manager (TFIM) before 6.2.2-TIV-TFIM-IF0011
* IBM Tivoli Federated Identity Manager (TFIM) after 6.2.2-TIV-TFIM-IF0011
In certain cases, IBM Tivoli Federated Identity Manager does not correctly handle end user provided data before using that data to construct an HTTP redirect request. If a compromised client can be caused to send a crafted request, that system could be induced to visit a malicious site without the awareness of the user of that system. The vulnerability can be accessed from a remote network, is of medium complexity and does not require authentication. A successful exploit could not compromise the confidentiality of the system, could partially compromise the integrity of the system and could not compromise the accessibility of the system.