[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

255116

 
 

909

 
 

198683

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2014-6092Date: (C)2015-04-28   (M)2023-12-22


IBM Curam Social Program Management (SPM) 5.2 before SP6 EP6, 6.0 SP2 before EP26, 6.0.4 before 6.0.4.6, and 6.0.5 before 6.0.5.6 requires failed-login handling for web-service accounts to have the same lockout policy as for standard user accounts, which makes it easier for remote attackers to cause a denial of service (web-service outage) by making many login attempts with a valid caseworker account name.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.0
Exploit Score: 10.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: NONE
Integrity: NONE
Availability: PARTIAL
  
Reference:
http://www-01.ibm.com/support/docview.wss?uid=swg21697742

CPE    11
cpe:/a:ibm:curam_social_program_management:6.0.4.0
cpe:/a:ibm:curam_social_program_management:6.0.4.5
cpe:/a:ibm:curam_social_program_management:6.0.5.4
cpe:/a:ibm:curam_social_program_management:6.0.4.4
...
CWE    1
CWE-17

© SecPod Technologies