CVE-2013-3040: Infoleak
IBM InfoSphere Information Server through 8.5 FP3, 8.7 through FP2, and 9.1 produces login-failure messages indicating whether the username or password is incorrect, which allows remote attackers to enumerate user accounts via a brute-force attack.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-3040?
CVE-2013-3040 is considered a medium severity vulnerability due to its potential for account enumeration via brute-force attacks.
How do I fix CVE-2013-3040?
To mitigate CVE-2013-3040, it's recommended to upgrade to a patched version of IBM InfoSphere Information Server and implement account lockout policies.
What are the affected versions of CVE-2013-3040?
CVE-2013-3040 affects IBM InfoSphere Information Server versions 8.5 up to FP3, 8.7 up to FP2, and 9.1.
Can CVE-2013-3040 be exploited remotely?
Yes, CVE-2013-3040 can be exploited remotely, allowing attackers to enumerate user accounts.
What type of attack is associated with CVE-2013-3040?
CVE-2013-3040 is associated with brute-force attacks, enabling attackers to determine valid usernames and passwords.