Vulnerability Details CVE-2008-7299
IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2 uses an incomplete SAML 1.x browser-artifact, which allows remote OpenID providers to spoof assertions via vectors related to the Issuer field.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 45.1%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2008-7299
-
cpe:2.3:a:ibm:tivoli_federated_identity_manager:6.2.0
-
cpe:2.3:a:ibm:tivoli_federated_identity_manager:6.2.0.1