CVE-2020-4891: Medium severity IBM Spectrum Scale vulnerability
IBM Spectrum Scale 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 uses an inadequate account lockout setting that could allow a local user er to brute force Rest API account credentials. IBM X-Force ID: 190974.
Other sources
IBM Spectrum Scale uses an inadequate account lockout setting that could allow a local user er to brute force Rest API account credentials.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-4891?
CVE-2020-4891 is a vulnerability found in IBM Spectrum Scale that allows a local user to brute force Rest API account credentials due to an inadequate account lockout setting.
What is the severity of CVE-2020-4891?
The severity of CVE-2020-4891 is medium (6.2).
How does CVE-2020-4891 affect IBM Spectrum Scale?
CVE-2020-4891 affects IBM Spectrum Scale versions 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2.
How can a local user exploit CVE-2020-4891?
A local user can exploit CVE-2020-4891 by performing a brute force attack on Rest API account credentials.
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-4891?
The Common Weakness Enumeration (CWE) ID for CVE-2020-4891 is CWE-307.