CVE Vulnerabilities

CVE-2013-5429

Improper Authentication

Published: Jan 21, 2014 | Modified: Aug 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:N/AC:H/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

The Risk Based Access functionality in IBM Tivoli Federated Identity Manager (TFIM) 6.2.2 before FP9 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.2 before FP9 does not prevent reuse of One Time Password (OTP) tokens, which makes it easier for remote authenticated users to complete transactions by leveraging access to an already-used token.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Tivoli_federated_identity_manager Ibm 6.2.2 (including) 6.2.2 (including)
Tivoli_federated_identity_manager Ibm 6.2.2.1 (including) 6.2.2.1 (including)
Tivoli_federated_identity_manager Ibm 6.2.2.2 (including) 6.2.2.2 (including)
Tivoli_federated_identity_manager Ibm 6.2.2.3 (including) 6.2.2.3 (including)
Tivoli_federated_identity_manager Ibm 6.2.2.4 (including) 6.2.2.4 (including)
Tivoli_federated_identity_manager Ibm 6.2.2.5 (including) 6.2.2.5 (including)
Tivoli_federated_identity_manager Ibm 6.2.2.6 (including) 6.2.2.6 (including)
Tivoli_federated_identity_manager Ibm 6.2.2.7 (including) 6.2.2.7 (including)
Tivoli_federated_identity_manager Ibm 6.2.2.8 (including) 6.2.2.8 (including)

Potential Mitigations

References