Inadequate Account Lockout Settings in IBM Security Verify Identity Manager
CVE-2022-22452

5.3MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
14 July 2022

Summary

IBM Security Verify Identity Manager version 10.0 has a vulnerability related to inadequate account lockout settings. This flaw could be exploited by remote attackers, enabling them to conduct brute force attacks and gain unauthorized access to user accounts. Ensuring strong account lockout measures is crucial to mitigate potential security risks associated with this vulnerability.

Affected Version(s)

Security Verify Governance 10.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.