Denial of Service Vulnerability in IBM Curam Social Program Management Web Services
CVE-2014-6092
Currently unrated
Summary
This vulnerability arises from improper handling of failed login attempts for web-service accounts in IBM Curam Social Program Management. Unlike standard user accounts, web-service accounts do not share the same lockout policy, allowing remote attackers to exploit valid caseworker account names to execute numerous login attempts. This may lead to a denial-of-service condition, potentially resulting in a web-service outage and interrupting critical operational services.
References
Timeline
Vulnerability published
Vulnerability Reserved