CVE-2015-5010

CWE-2543 documents3 sources
Severity
7.5HIGH
EPSS
0.3%
top 48.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 15
Latest updateMay 17

Description

IBM Security Access Manager for Web 7.0 before 7.0.0 IF21, 8.0 before 8.0.1.3 IF4, and 9.0 before 9.0.0.1 IF1 does not have a lockout mechanism for invalid login attempts, which makes it easier for remote attackers to obtain access via a brute-force attack.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-h6c2-gw9r-pq98: IBM Security Access Manager for Web 72022-05-17
CVEList
CVE-2015-5010: IBM Security Access Manager for Web 72016-02-15