First published: Mon Aug 12 2024(Updated: )
IBM Common Licensing 9.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 297895.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Rational Common Licensing | =9.0 | |
IBM Rational Common Licensing | <=Agent 9.0 | |
IBM Rational Common Licensing | <=ART 9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-40697 has a moderate severity level due to its potential for account compromise via weak password policies.
To mitigate CVE-2024-40697, you should enforce strong password policies for users in IBM Common Licensing.
CVE-2024-40697 affects IBM Common Licensing version 9.0 including Agent 9.0 and ART 9.0.
Yes, CVE-2024-40697 can be exploited remotely if weak passwords are in use, making user accounts vulnerable.
To prevent CVE-2024-40697, implement multi-factor authentication alongside strong password requirements for all user accounts.