Lucene search

K
cveIbmCVE-2016-3025
HistoryNov 25, 2016 - 3:59 a.m.

CVE-2016-3025

2016-11-2503:59:06
CWE-254
ibm
web.nvd.nist.gov
29
2
ibm
security access manager
cve-2016-3025
nvd
access management
brute-force
security vulnerability

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

7.7

Confidence

High

EPSS

0.015

Percentile

87.0%

IBM Security Access Manager for Mobile 8.x before 8.0.1.4 IF3 and Security Access Manager 9.x before 9.0.1.0 IF5 do not properly restrict failed login attempts, which makes it easier for remote attackers to obtain access via a brute-force approach.

Affected configurations

Nvd
Node
ibmsecurity_access_managerMatch9.0.0
OR
ibmsecurity_access_managerMatch9.0.0.1
OR
ibmsecurity_access_managerMatch9.0.1.0
OR
ibmsecurity_access_manager_for_mobileMatch8.0.0.0
OR
ibmsecurity_access_manager_for_mobileMatch8.0.0.1
OR
ibmsecurity_access_manager_for_mobileMatch8.0.0.2
OR
ibmsecurity_access_manager_for_mobileMatch8.0.0.3
OR
ibmsecurity_access_manager_for_mobileMatch8.0.0.4
OR
ibmsecurity_access_manager_for_mobileMatch8.0.0.5
OR
ibmsecurity_access_manager_for_mobileMatch8.0.1
OR
ibmsecurity_access_manager_for_mobileMatch8.0.1.2
OR
ibmsecurity_access_manager_for_mobileMatch8.0.1.3
OR
ibmsecurity_access_manager_for_mobileMatch8.0.1.4
VendorProductVersionCPE
ibmsecurity_access_manager9.0.0cpe:2.3:a:ibm:security_access_manager:9.0.0:*:*:*:*:*:*:*
ibmsecurity_access_manager9.0.0.1cpe:2.3:a:ibm:security_access_manager:9.0.0.1:*:*:*:*:*:*:*
ibmsecurity_access_manager9.0.1.0cpe:2.3:a:ibm:security_access_manager:9.0.1.0:*:*:*:*:*:*:*
ibmsecurity_access_manager_for_mobile8.0.0.0cpe:2.3:a:ibm:security_access_manager_for_mobile:8.0.0.0:*:*:*:*:*:*:*
ibmsecurity_access_manager_for_mobile8.0.0.1cpe:2.3:a:ibm:security_access_manager_for_mobile:8.0.0.1:*:*:*:*:*:*:*
ibmsecurity_access_manager_for_mobile8.0.0.2cpe:2.3:a:ibm:security_access_manager_for_mobile:8.0.0.2:*:*:*:*:*:*:*
ibmsecurity_access_manager_for_mobile8.0.0.3cpe:2.3:a:ibm:security_access_manager_for_mobile:8.0.0.3:*:*:*:*:*:*:*
ibmsecurity_access_manager_for_mobile8.0.0.4cpe:2.3:a:ibm:security_access_manager_for_mobile:8.0.0.4:*:*:*:*:*:*:*
ibmsecurity_access_manager_for_mobile8.0.0.5cpe:2.3:a:ibm:security_access_manager_for_mobile:8.0.0.5:*:*:*:*:*:*:*
ibmsecurity_access_manager_for_mobile8.0.1cpe:2.3:a:ibm:security_access_manager_for_mobile:8.0.1:*:*:*:*:*:*:*
Rows per page:
1-10 of 131

Social References

More

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

7.7

Confidence

High

EPSS

0.015

Percentile

87.0%

Related for CVE-2016-3025