PT-2024-28989 · Ibm · Ibm Common Licensing

Published

2024-08-13

·

Updated

2024-08-22

·

CVE-2024-40697

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Common Licensing version 9.0
Description The issue is related to weak password requirements in IBM Common Licensing, making it easier for attackers to compromise user accounts due to the lack of strong password enforcement by default. This increases the risk of unauthorized access.
Recommendations For IBM Common Licensing version 9.0, upgrade the affected component immediately to mitigate risks. As a temporary workaround, consider enforcing strong password policies manually until a patch is available. Restrict access to sensitive areas of the system to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-40697

Affected Products

Ibm Common Licensing