CVE-2024-40684

MEDIUM

IBM Operations Analytics - Log Analysis is affected by Weak Password Policy and Inadequate Account Lockout Mechanism

Title source: cna
STIX 2.1

Description

IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4 IBM SmartCloud Analytics - Log Analysis does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory patch
https://www.ibm.com/support/pages/node/7268536

Scores

CVSS v3 5.9
EPSS 0.0036
EPSS Percentile 27.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-521
Status published
Products (18)
IBM/Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3 - 7.2.0.14
IBM/Operations Analytics - Log Analysis 1.3.6.0, 1.3.6.1
IBM/Operations Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2
IBM/Operations Analytics - Log Analysis 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4
ibm/operations_analytics_log_analysis 1.3.5.0
ibm/operations_analytics_log_analysis 1.3.5.1
ibm/operations_analytics_log_analysis 1.3.5.2
ibm/operations_analytics_log_analysis 1.3.5.3
ibm/operations_analytics_log_analysis 1.3.6.0
ibm/operations_analytics_log_analysis 1.3.6.1
... and 8 more
Published May 27, 2026
Tracked Since May 27, 2026