PT-2016-5334 · Ibm · Ibm Security Access Manager+1
Chris Shepherd
+6
·
Published
2016-11-25
·
Updated
2016-11-28
·
CVE-2016-3025
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IBM Security Access Manager for Mobile versions 8.x before 8.0.1.4 IF3
IBM Security Access Manager versions 9.x before 9.0.1.0 IF5
Description
The issue allows remote attackers to obtain access via a brute-force approach due to insufficient restriction of failed login attempts.
Recommendations
For IBM Security Access Manager for Mobile versions 8.x before 8.0.1.4 IF3, update to version 8.0.1.4 IF3 or later.
For IBM Security Access Manager versions 9.x before 9.0.1.0 IF5, update to version 9.0.1.0 IF5 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Security Access Manager
Ibm Security Access Manager For Mobile