First published: Fri Jan 12 2018(Updated: )
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 do not properly restrict failed login attempts, which makes it easier for remote attackers to obtain access via a brute-force approach. IBM X-Force ID: 111695.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Identity Manager Virtual Appliance | =7.0.0.0 | |
IBM Security Identity Manager Virtual Appliance | =7.0.0.1 | |
IBM Security Identity Manager Virtual Appliance | =7.0.0.2 | |
IBM Security Identity Manager Virtual Appliance | =7.0.0.3 | |
IBM Security Identity Manager Virtual Appliance | =7.0.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this IBM Security Identity Manager (ISIM) Virtual Appliance vulnerability is CVE-2016-0332.
The severity level of CVE-2016-0332 is critical.
The affected versions of IBM Security Identity Manager Virtual Appliance for this vulnerability are 7.0.0.0, 7.0.0.1, 7.0.0.2, 7.0.0.3, and 7.0.1.0.
Remote attackers can exploit this vulnerability by using a brute-force approach to obtain access.
Yes, there are references available for this vulnerability. You can find them at the following URLs: [http://www-01.ibm.com/support/docview.wss?uid=swg21981438](http://www-01.ibm.com/support/docview.wss?uid=swg21981438) and [https://exchange.xforce.ibmcloud.com/vulnerabilities/111695](https://exchange.xforce.ibmcloud.com/vulnerabilities/111695).