CVE-2020-4891

CWE-3073 documents3 sources
Severity
5.5MEDIUM
EPSS
0.0%
top 88.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 16
Latest updateMay 24

Description

IBM Spectrum Scale 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 uses an inadequate account lockout setting that could allow a local user er to brute force Rest API account credentials. IBM X-Force ID: 190974.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

NVDibm/spectrum_scale5.0.0.05.0.5.5+1
CVEListV5ibm/spectrum_scale4 versions+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-pp7w-jhfx-v9pw: IBM Spectrum Scale 52022-05-24
CVEList
CVE-2020-4891: IBM Spectrum Scale 52021-03-16
CVE-2020-4891 (MEDIUM CVSS 5.5) | IBM Spectrum Scale 5.0.0 through 5. | cvebase.io