First published: Wed Feb 07 2024(Updated: )
IBM Engineering Lifecycle Optimization 7.0.2 and 7.0.3 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 268755.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Pub | <=7.0.3 | |
IBM Pub | <=7.0.2 | |
IBM Engineering Lifecycle Optimization | =7.0.2 | |
IBM Engineering Lifecycle Optimization | =7.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-45191 has a severity rating indicating a medium-level risk due to the potential for account brute force attacks.
To fix CVE-2023-45191, update IBM Engineering Lifecycle Optimization to version 7.0.4 or later, which addresses the inadequate account lockout configuration.
CVE-2023-45191 affects IBM Engineering Lifecycle Optimization versions 7.0.2 and 7.0.3.
CVE-2023-45191 can allow remote attackers to perform brute force attacks to gain unauthorized access to user accounts.
A recommended workaround for CVE-2023-45191 is to implement stronger account lockout policies or monitor login attempts until an update can be applied.