CVE Vulnerabilities

CVE-2013-5429

Improper Authentication

Published: Jan 21, 2014 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:N/AC:H/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Risk Based Access functionality in IBM Tivoli Federated Identity Manager (TFIM) 6.2.2 before FP9 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.2 before FP9 does not prevent reuse of One Time Password (OTP) tokens, which makes it easier for remote authenticated users to complete transactions by leveraging access to an already-used token.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
Tivoli_federated_identity_managerIbm6.2.2 (including)6.2.2 (including)
Tivoli_federated_identity_managerIbm6.2.2.1 (including)6.2.2.1 (including)
Tivoli_federated_identity_managerIbm6.2.2.2 (including)6.2.2.2 (including)
Tivoli_federated_identity_managerIbm6.2.2.3 (including)6.2.2.3 (including)
Tivoli_federated_identity_managerIbm6.2.2.4 (including)6.2.2.4 (including)
Tivoli_federated_identity_managerIbm6.2.2.5 (including)6.2.2.5 (including)
Tivoli_federated_identity_managerIbm6.2.2.6 (including)6.2.2.6 (including)
Tivoli_federated_identity_managerIbm6.2.2.7 (including)6.2.2.7 (including)
Tivoli_federated_identity_managerIbm6.2.2.8 (including)6.2.2.8 (including)

Potential Mitigations

References