Inadequate Account Lockout Configurations in IBM Spectrum Scale
CVE-2020-4891
6.2MEDIUM
Summary
IBM Spectrum Scale versions 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 feature inadequate account lockout settings. This vulnerability potentially enables a local user to perform brute force attacks against REST API account credentials, compromising the security of the application. Organizations using these versions are advised to review their account configurations and implement stronger lockout policies to mitigate the risk of unauthorized access.
Affected Version(s)
Spectrum Scale 5.0.0
Spectrum Scale 5.0.5.5
Spectrum Scale 5.1.0
References
CVSS V3.1
Score:
6.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved