CVE-2012-3310: IBM Tivoli Federated Identity Manager

Low severity, CVSS 3.5. EPSS: 0.9% chance of exploitation in the next 30 days.

IBM Tivoli Federated Identity Manager (TFIM) before 6.1.1.14, 6.2.0 before 6.2.0.12, and 6.2.1 before 6.2.1.4 allows context-dependent attackers to discover (1) a cleartext LDAP Bind Password, (2) keystore passwords, (3) a cleartext Basic Authentication password from a client, or (4) a cleartext user password by leveraging a logging configuration with a log trace setting of all.

Affected products

  • IBM Tivoli Federated Identity Manager: up to and including 6.1.1.13; version 6.1.1 only; version 6.1.1.12 only; version 6.2.0 only; version 6.2.0.1 only; version 6.2.0.2 only; …

Published 2013-01-17. Last modified 2026-06-16.