Inadequate Account Lockout Configurations in IBM Spectrum Scale
CVE-2020-4891

6.2MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
16 March 2021

Summary

IBM Spectrum Scale versions 5.0.0 through 5.0.5.5 and 5.1.0 through 5.1.0.2 feature inadequate account lockout settings. This vulnerability potentially enables a local user to perform brute force attacks against REST API account credentials, compromising the security of the application. Organizations using these versions are advised to review their account configurations and implement stronger lockout policies to mitigate the risk of unauthorized access.

Affected Version(s)

Spectrum Scale 5.0.0

Spectrum Scale 5.0.5.5

Spectrum Scale 5.1.0

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.