CyberRota
Live Feed
Return to register
Case File

CVE-2011-3138

MEDIUM · CVSS 5 EPSS 1.76%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2011-08-12 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2011-3138
Severity
MEDIUM
CVSS
5
EPSS
1.76%
Java

Original Filing — NVD Description

The LTPA STS module support implementation in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.9 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.0 before 6.2.0.9 relies on a static instance of a Java Development Kit (JDK) class, which might allow attackers to bypass LTPA token signature verification by leveraging lack of thread safety.