Overview
- Description
- IBM Security Access Manager Container 10.0.0.0 through 10.0.6.1 does not require that docker images should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 261196.
- Source
- psirt@us.ibm.com
- NVD status
- Analyzed
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Severity
- HIGH
Weaknesses
- psirt@us.ibm.com
- CWE-521
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:ibm:security_access_manager_container:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "408F2EBF-CCE3-47A8-B835-1C71CA62777E", "versionEndIncluding": "10.0.6.1", "versionStartIncluding": "10.0.0.0" } ], "operator": "OR" } ] } ]