Inadequate Account Lockout Settings in IBM Security Verify Identity Manager
CVE-2022-22452
5.3MEDIUM
Summary
IBM Security Verify Identity Manager version 10.0 has a vulnerability related to inadequate account lockout settings. This flaw could be exploited by remote attackers, enabling them to conduct brute force attacks and gain unauthorized access to user accounts. Ensuring strong account lockout measures is crucial to mitigate potential security risks associated with this vulnerability.
Affected Version(s)
Security Verify Governance 10.0
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved