CVE-2021-38890: High severity ibm sterling connect:direct vulnerability
IBM Sterling Connect:Direct Web Services 1.0 and 6.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 209507.
Other sources
IBM Sterling Connect:Direct Web Services uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-38890?
CVE-2021-38890 has been classified with a medium severity level due to its potential for brute force attacks.
How do I fix CVE-2021-38890?
To remediate CVE-2021-38890, you should configure stronger account lockout policies in IBM Sterling Connect:Direct Web Services.
Which versions of IBM Sterling Connect:Direct are affected by CVE-2021-38890?
CVE-2021-38890 affects IBM Sterling Connect:Direct Web Services versions 1.0 and 6.0.
Can CVE-2021-38890 be exploited remotely?
Yes, a remote attacker can exploit CVE-2021-38890 to brute force account credentials.
Is there a workaround for CVE-2021-38890?
Implementing stricter account lockout policies serves as a temporary workaround for CVE-2021-38890.