First published: Thu Mar 04 2021(Updated: )
IBM Spectrum Scale 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 uses an inadequate account lockout setting that could allow a local user er to brute force Rest API account credentials. IBM X-Force ID: 190974.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Spectrum Scale | >=5.0.0.0<=5.0.5.5 | |
IBM Spectrum Scale | >=5.1.0.0<=5.1.0.2 | |
<=5.0.0 - 5.0.5.5 | ||
<=5.1.0 - 5.1.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-4891 is a vulnerability found in IBM Spectrum Scale that allows a local user to brute force Rest API account credentials due to an inadequate account lockout setting.
The severity of CVE-2020-4891 is medium (6.2).
CVE-2020-4891 affects IBM Spectrum Scale versions 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2.
A local user can exploit CVE-2020-4891 by performing a brute force attack on Rest API account credentials.
The Common Weakness Enumeration (CWE) ID for CVE-2020-4891 is CWE-307.