Vulnerability Description
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 do not properly restrict failed login attempts, which makes it easier for remote attackers to obtain access via a brute-force approach. IBM X-Force ID: 111695.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Security Identity Manager Virtual Appliance | 7.0.0.0 |
Related Weaknesses (CWE)
References
- http://www-01.ibm.com/support/docview.wss?uid=swg21981438PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/111695VDB EntryVendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21981438PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/111695VDB EntryVendor Advisory
FAQ
What is CVE-2016-0332?
CVE-2016-0332 is a vulnerability with a CVSS score of 9.8 (CRITICAL). IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 do not properly restrict failed login attempts, which makes it easier for remote attackers to...
How severe is CVE-2016-0332?
CVE-2016-0332 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2016-0332?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Security Identity Manager Virtual Appliance.