Denial of Service Vulnerability in IBM Curam Social Program Management Web Services
CVE-2014-6092

Currently unrated

Key Information:

Vendor
IBM
Vendor
CVE Published:
27 April 2015

Summary

This vulnerability arises from improper handling of failed login attempts for web-service accounts in IBM Curam Social Program Management. Unlike standard user accounts, web-service accounts do not share the same lockout policy, allowing remote attackers to exploit valid caseworker account names to execute numerous login attempts. This may lead to a denial-of-service condition, potentially resulting in a web-service outage and interrupting critical operational services.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.