CVE-2020-4232
HIGHIBM Security Identity Governance and Intelligence 5.2.6 - Username Enumeration via Excessive Authentication Attempts
Title source: llmDescription
IBM Security Identity Governance and Intelligence 5.2.6 could allow an attacker to enumerate usernames to find valid login credentials which could be used to attempt further attacks against the system. IBM X-Force ID: 175336.
References (2)
Core 2
Core References
Patch, Vendor Advisory x_refsource_confirm
https://www.ibm.com/support/pages/node/6207906
VDB Entry, Vendor Advisory vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/175336
Scores
CVSS v3
7.5
EPSS
0.0112
EPSS Percentile
62.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-307
Status
published
Products (1)
ibm/security_identity_governance_and_intelligence
5.2.6
Published
May 28, 2020
Tracked Since
Feb 18, 2026