CVE-2016-3025
HIGHIBM Security Access Manager and Security Access Manager for Mobile - Unauthenticated Brute-Force Login
Title source: llmDescription
IBM Security Access Manager for Mobile 8.x before 8.0.1.4 IF3 and Security Access Manager 9.x before 9.0.1.0 IF5 do not properly restrict failed login attempts, which makes it easier for remote attackers to obtain access via a brute-force approach.
References (4)
Core 4
Core References
Broken Link vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IV89258
Broken Link vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IV89240
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/93178
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21991107
Scores
CVSS v3
8.1
EPSS
0.0160
EPSS Percentile
73.3%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-254
Status
published
Products (13)
ibm/security_access_manager
9.0.0
ibm/security_access_manager
9.0.0.1
ibm/security_access_manager
9.0.1.0
ibm/security_access_manager_for_mobile
8.0.0.0
ibm/security_access_manager_for_mobile
8.0.0.1
ibm/security_access_manager_for_mobile
8.0.0.2
ibm/security_access_manager_for_mobile
8.0.0.3
ibm/security_access_manager_for_mobile
8.0.0.4
ibm/security_access_manager_for_mobile
8.0.0.5
ibm/security_access_manager_for_mobile
8.0.1
... and 3 more
Published
Nov 25, 2016
Tracked Since
Feb 18, 2026