CVE-2018-1680
MEDIUMIBM Security Privileged Identity Manager Virtual Appliance <2.2.1 -...
Title source: llmDescription
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 145236.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
http://www.ibm.com/support/docview.wss?uid=ibm10879093
VDB Entry, Vendor Advisory vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/145236
Scores
CVSS v3
5.9
EPSS
0.0148
EPSS Percentile
70.5%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-521
Status
published
Products (1)
ibm/security_privileged_identity_manager
2.1.1
Published
Apr 02, 2019
Tracked Since
Feb 18, 2026