CVE-2023-45191: IBM Engineering Lifecycle Optimization information disclosure
IBM Engineering Lifecycle Optimization 7.0.2 and 7.0.3 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 268755.
Other sources
IBM Engineering Lifecycle Optimization uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-45191?
CVE-2023-45191 has a severity rating indicating a medium-level risk due to the potential for account brute force attacks.
How do I fix CVE-2023-45191?
To fix CVE-2023-45191, update IBM Engineering Lifecycle Optimization to version 7.0.4 or later, which addresses the inadequate account lockout configuration.
Which versions of IBM products are affected by CVE-2023-45191?
CVE-2023-45191 affects IBM Engineering Lifecycle Optimization versions 7.0.2 and 7.0.3.
What kind of attacks can CVE-2023-45191 allow?
CVE-2023-45191 can allow remote attackers to perform brute force attacks to gain unauthorized access to user accounts.
Is there a workaround for CVE-2023-45191 before applying a fix?
A recommended workaround for CVE-2023-45191 is to implement stronger account lockout policies or monitor login attempts until an update can be applied.