PT-2017-8891 · Ibm · Ibm Tivoli Key Lifecycle Manager

Publicado

2017-02-02

·

Atualizado

2017-02-07

·

CVE-2016-6095

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM Tivoli Key Lifecycle Manager versions 2.5 through 2.6
Description The issue is related to an inadequate account lockout setting, which could allow a remote attacker to brute force account credentials.
Recommendations For versions 2.5 and 2.6, consider implementing a more robust account lockout policy to prevent brute force attacks.

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-6095

Produtos afetados

Ibm Tivoli Key Lifecycle Manager