CVE-2013-5429
Last modified
CVE-2013-5429 is a vulnerability of currently unknown severity. The Risk Based Access functionality in IBM Tivoli Federated Identity Manager (TFIM) 6.2.2 before FP9 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.2 before FP9 does not prevent reuse of One Time Password (OTP) tokens, which makes it easier for remote authenticated users to complete transactions by leveraging access to an already-used token.. EPSS estimates a 0.91% chance of exploitation in the next 30 days.
Description
The Risk Based Access functionality in IBM Tivoli Federated Identity Manager (TFIM) 6.2.2 before FP9 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.2 before FP9 does not prevent reuse of One Time Password (OTP) tokens, which makes it easier for remote authenticated users to complete transactions by leveraging access to an already-used token.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Tivoli Federated Identity Manager | 6.2.2 |
| Ibm | Tivoli Federated Identity Manager | 6.2.2.1 |
| Ibm | Tivoli Federated Identity Manager | 6.2.2.2 |
| Ibm | Tivoli Federated Identity Manager | 6.2.2.3 |
| Ibm | Tivoli Federated Identity Manager | 6.2.2.4 |
| Ibm | Tivoli Federated Identity Manager | 6.2.2.5 |
| Ibm | Tivoli Federated Identity Manager | 6.2.2.6 |
| Ibm | Tivoli Federated Identity Manager | 6.2.2.7 |
| Ibm | Tivoli Federated Identity Manager | 6.2.2.8 |
References
- http://www-01.ibm.com/support/docview.wss?uid=swg21660509Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21660510Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21660509Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21660510Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-5429?
How severe is CVE-2013-5429?
How do I fix CVE-2013-5429?
Are you affected by CVE-2013-5429?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
