First published: Fri Jun 07 2019(Updated: )
IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 157012.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Intelligent Operations Center | >=5.1.0<=5.2.0 | |
IBM Intelligent Operations Center for Emergency Management | >=5.1.0<=5.1.0.6 | |
IBM Water Operations for Waternamics | >=5.1.0<=5.2.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4067 is a vulnerability in IBM Intelligent Operations Center (IOC) versions 5.1.0 through 5.2.0, where strong passwords are not required by default, making it easier for attackers to compromise user accounts.
CVE-2019-4067 has a severity rating of 7.5 (high).
IBM Intelligent Operations Center (IOC) versions 5.1.0 through 5.2.0, IBM Intelligent Operations Center for Emergency Management versions 5.1.0 through 5.1.0.6, and IBM Water Operations for Waternamics versions 5.1.0 through 5.2.1.1 are affected by CVE-2019-4067.
Attackers can exploit CVE-2019-4067 by taking advantage of the weak password requirement in IBM Intelligent Operations Center, making it easier for them to compromise user accounts.
Yes, IBM has released a security bulletin with details on how to mitigate the vulnerability in CVE-2019-4067. Please refer to the IBM support website for more information.