IBM Security Access Manager for Mobile 8.x before 8.0.1.4 IF3 and Security Access Manager 9.x before 9.0.1.0 IF5 do not properly restrict failed login attempts, which makes it easier for remote attackers to obtain access via a brute-force approach.
References
Link | Resource |
---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg1IV89240 | Broken Link |
http://www-01.ibm.com/support/docview.wss?uid=swg1IV89258 | Broken Link |
http://www-01.ibm.com/support/docview.wss?uid=swg21991107 | Vendor Advisory |
http://www.securityfocus.com/bid/93178 |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: ibm
Published: 2016-11-25T03:38:00
Updated: 2016-11-25T19:57:01
Reserved: 2016-03-09T00:00:00
Link: CVE-2016-3025
JSON object: View
NVD Information
Status : Modified
Published: 2016-11-25T03:59:06.530
Modified: 2016-11-28T20:05:57.577
Link: CVE-2016-3025
JSON object: View
Redhat Information
No data.
CWE