Overview
- Description
- IBM Cloud Pak System 2.3.1.1, 2.3.2.0, and 2.3.3.7 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 260733.
- Source
- psirt@us.ibm.com
- NVD status
- Analyzed
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity
- HIGH
Weaknesses
- psirt@us.ibm.com
- CWE-307
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:ibm:cloud_pak_system:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A28FDA5D-1220-4585-97AF-A9349CFB3971", "versionEndIncluding": "2.3.3.6", "versionStartIncluding": "2.3.3.0" }, { "criteria": "cpe:2.3:a:ibm:cloud_pak_system:2.3.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A7D9DA5D-895C-45D9-909C-9C04454A1BB8" }, { "criteria": "cpe:2.3:a:ibm:cloud_pak_system:2.3.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F5153F3A-2257-42A5-AA87-4387D374C7BB" }, { "criteria": "cpe:2.3:a:ibm:cloud_pak_system:2.3.3.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1A41D520-7446-441A-B488-5B98CF7CA8D3" } ], "operator": "OR" } ] } ]