CVE-2013-3040
Published Aug 16, 2013
Last updated 7 years ago
Overview
- Description
- IBM InfoSphere Information Server through 8.5 FP3, 8.7 through FP2, and 9.1 produces login-failure messages indicating whether the username or password is incorrect, which allows remote attackers to enumerate user accounts via a brute-force attack.
- Source
- psirt@us.ibm.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-200
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:ibm:infosphere_information_server:8.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CA7096B4-291F-49BB-8DBC-E67AC901CF08" }, { "criteria": "cpe:2.3:a:ibm:infosphere_information_server:8.5.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D547E88D-FE3F-4C90-B7D8-301A1449E9AB" }, { "criteria": "cpe:2.3:a:ibm:infosphere_information_server:8.5.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5585D2C4-6575-4469-A6EF-CCDC3A0BEDB2" }, { "criteria": "cpe:2.3:a:ibm:infosphere_information_server:8.5.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "57FEAC62-FF71-4AFC-B907-C0AC5301FB35" }, { "criteria": "cpe:2.3:a:ibm:infosphere_information_server:8.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "42A9CF5C-79EC-4BBF-92AF-2AB3DC125684" }, { "criteria": "cpe:2.3:a:ibm:infosphere_information_server:8.7.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8C940220-98F4-41FC-93BE-6D33D4AE9447" }, { "criteria": "cpe:2.3:a:ibm:infosphere_information_server:8.7.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "71FEBA37-59D9-4BE0-8072-3BB60832BDB5" }, { "criteria": "cpe:2.3:a:ibm:infosphere_information_server:9.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F3BF0A4B-5DDB-420D-B1F2-8C1ED23F60CF" } ], "operator": "OR" } ] } ]