CVE-2013-3040Sensitive Information Exposure in IBM Infosphere Information Server

Severity
5.0MEDIUMNVD
EPSS
0.3%
top 51.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 16
Latest updateMay 17

Description

IBM InfoSphere Information Server through 8.5 FP3, 8.7 through FP2, and 9.1 produces login-failure messages indicating whether the username or password is incorrect, which allows remote attackers to enumerate user accounts via a brute-force attack.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-x3wc-cq8w-x9q6: IBM InfoSphere Information Server through 82022-05-17
CVEList
CVE-2013-3040: IBM InfoSphere Information Server through 82013-08-16
CVE-2013-3040 — Sensitive Information Exposure in IBM | cvebase