First published: Mon Jan 14 2019(Updated: )
IBM Security Identity Manager 6.0.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 153628.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Identity Manager | >=6.0.0<=6.0.0.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1956 is a vulnerability in IBM Security Identity Manager 6.0.0 that allows attackers to compromise user accounts by not requiring strong passwords by default.
CVE-2018-1956 affects IBM Security Identity Manager 6.0.0 by not enforcing strong passwords for user accounts by default.
CVE-2018-1956 has a severity rating of 7.5, which is considered high.
Attackers can exploit CVE-2018-1956 by taking advantage of the lack of strong password requirements in IBM Security Identity Manager 6.0.0.
The Common Weakness Enumeration (CWE) for CVE-2018-1956 is CWE-521.