PT-2016-5334 · Ibm · Ibm Security Access Manager+1

Chris Shepherd

+6

·

Published

2016-11-25

·

Updated

2016-11-28

·

CVE-2016-3025

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM Security Access Manager for Mobile versions 8.x before 8.0.1.4 IF3 IBM Security Access Manager versions 9.x before 9.0.1.0 IF5
Description The issue allows remote attackers to obtain access via a brute-force approach due to insufficient restriction of failed login attempts.
Recommendations For IBM Security Access Manager for Mobile versions 8.x before 8.0.1.4 IF3, update to version 8.0.1.4 IF3 or later. For IBM Security Access Manager versions 9.x before 9.0.1.0 IF5, update to version 9.0.1.0 IF5 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-3025

Affected Products

Ibm Security Access Manager
Ibm Security Access Manager For Mobile