CVE-2015-1966
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
04/07/2015
Last modified:
12/04/2025
Description
Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before FP17, 6.2.1 before FP9, and 6.2.2 before FP15, as used in Security Access Manager for Mobile and other products, allow remote attackers to inject arbitrary web script or HTML via a crafted URL, related to the (1) ERROR_DESCRIPTION and (2) TOKEN:RelayState macros.
Impact
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:ibm:tivoli_federated_identity_manager:6.2.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:tivoli_federated_identity_manager:6.2.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:tivoli_federated_identity_manager:6.2.2:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV74198
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV74199
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV74200
- http://www-01.ibm.com/support/docview.wss?uid=swg21959071
- http://www.securityfocus.com/bid/75537
- http://www.securitytracker.com/id/1032767
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV74198
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV74199
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV74200
- http://www-01.ibm.com/support/docview.wss?uid=swg21959071
- http://www.securityfocus.com/bid/75537
- http://www.securitytracker.com/id/1032767



