CVE-2014-6092: Medium severity ibm curam social program management vulnerability
IBM Curam Social Program Management (SPM) 5.2 before SP6 EP6, 6.0 SP2 before EP26, 6.0.4 before 6.0.4.6, and 6.0.5 before 6.0.5.6 requires failed-login handling for web-service accounts to have the same lockout policy as for standard user accounts, which makes it easier for remote attackers to cause a denial of service (web-service outage) by making many login attempts with a valid caseworker account name.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6092?
CVE-2014-6092 has a medium severity level due to its impact on failed-login handling for web-service accounts.
How do I fix CVE-2014-6092?
To fix CVE-2014-6092, update IBM Curam Social Program Management to version 6.0.5.6 or later.
What versions of IBM Curam Social Program Management are affected by CVE-2014-6092?
CVE-2014-6092 affects versions before SP6 EP6 for 5.2 and versions before EP26 for 6.0 SP2, including certain early 6.0.4 and 6.0.5 releases.
What are the risks associated with CVE-2014-6092?
The risks associated with CVE-2014-6092 include potential unauthorized access due to insufficient lockout policies for web-service accounts.
When was CVE-2014-6092 disclosed?
CVE-2014-6092 was disclosed in 2014, highlighting vulnerabilities in IBM Curam Social Program Management.