Lucene search

K
ibmIBM05EE31E092246FCCFFDBB35C2A9F096309E62830E92B3784807489333296092C
HistoryJun 16, 2018 - 9:46 p.m.

Security Bulletin: A vulnerability associated with the default account lockout settings in IBM Security Access Manager for Web has been identified (CVE-2016-3025)

2018-06-1621:46:22
www.ibm.com
10

EPSS

0.015

Percentile

87.0%

Summary

The default account lockout setting in IBM Security Access Manager for Web could allow a remote attacker to use brute force to discover account credentials.

Vulnerability Details

CVEID: CVE-2016-3025**
DESCRIPTION:** IBM Security Access Manager for Web uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.
CVSS Base Score: 7.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/114473 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

IBM Security Access Manager for Web 7.0 appliances

IBM Security Access Manager for Web 8.0, all firmware versions

IBM Security Access Manager 9.0, all firmware versions

Remediation/Fixes

IBM has provided patches for all affected versions. Follow the installation instructions in the README files included with the patch.

Product VRMF APAR Remediation
IBM Security Access Manager for Web 7.0 (appliance) IV89294 Apply Interim Fix 27:
7.0.0-ISS-WGA-IF0027
IBM Security Access Manager for Web 8.0.0.0 -
8.0.1.4 IV89317 1. For versions prior to 8.0.1.4, upgrade to 8.0.1.4:
8.0.1-ISS-WGA-FP0004
2. Apply 8.0.1.4 Interim Fix 3:
8.0.1.4-ISS-WGA-IF0003
IBM Security Access Manager 9.0 IV89240 1. For versions prior to 9.0.1.0, upgrade to 9.0.1.0:
IBM Security Access Manager V9.0.1 Multiplatform, Multilingual (CRW4EML)
2. Apply 9.0.1.0 Interim Fix 5:
9.0.1.0-ISS-ISAM-IF0005

Workarounds and Mitigations

None.

EPSS

0.015

Percentile

87.0%

Related for 05EE31E092246FCCFFDBB35C2A9F096309E62830E92B3784807489333296092C