Brute-force attack in IBM Security Guardium Big Data Intelligence

Published: 2018-03-07 12:17:04
Severity Low
Patch available YES
Number of vulnerabilities 1
CVE ID CVE-2018-1373
CVSSv3 6.5 [CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C]
CWE ID CWE-200
Exploitation vector Network
Public exploit N/A
Vulnerable software IBM Security Guardium Big Data Intelligence
Vulnerable software versions IBM Security Guardium Big Data Intelligence 3.1
Vendor URL IBM Corporation

Security Advisory

1) Brute-force attack

Description

The vulnerability allows a remote attacker to obtain potentially sensitive information.

The weakness exists due to improper lockout of accounts on authentication failure. A remote attacker can conduct a brute force password guessing attack and gain access to potentially sensitive information.

Remediation

Update to version 3.2.

External links

http://www-01.ibm.com/support/docview.wss?uid=swg22013750

Back to List