PT-2024-28989 · Ibm · Ibm Common Licensing
Published
2024-08-13
·
Updated
2024-08-22
·
CVE-2024-40697
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Common Licensing version 9.0
Description
The issue is related to weak password requirements in IBM Common Licensing, making it easier for attackers to compromise user accounts due to the lack of strong password enforcement by default. This increases the risk of unauthorized access.
Recommendations
For IBM Common Licensing version 9.0, upgrade the affected component immediately to mitigate risks. As a temporary workaround, consider enforcing strong password policies manually until a patch is available. Restrict access to sensitive areas of the system to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Common Licensing