CVE-2024-40684
MEDIUMIBM Operations Analytics - Log Analysis is affected by Weak Password Policy and Inadequate Account Lockout Mechanism
Title source: cnaDescription
IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4 IBM SmartCloud Analytics - Log Analysis does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
References (1)
Core 1
Core References
Vendor Advisory vendor-advisory
patch
https://www.ibm.com/support/pages/node/7268536
Scores
CVSS v3
5.9
EPSS
0.0036
EPSS Percentile
27.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-521
Status
published
Products (18)
IBM/Operations Analytics - Log Analysis
1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3 - 7.2.0.14
IBM/Operations Analytics - Log Analysis
1.3.6.0, 1.3.6.1
IBM/Operations Analytics - Log Analysis
1.3.7.0, 1.3.7.1, 1.3.7.2
IBM/Operations Analytics - Log Analysis
1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4
ibm/operations_analytics_log_analysis
1.3.5.0
ibm/operations_analytics_log_analysis
1.3.5.1
ibm/operations_analytics_log_analysis
1.3.5.2
ibm/operations_analytics_log_analysis
1.3.5.3
ibm/operations_analytics_log_analysis
1.3.6.0
ibm/operations_analytics_log_analysis
1.3.6.1
... and 8 more
Published
May 27, 2026
Tracked Since
May 27, 2026