CVE-2016-3025

EUVD-2016-4098
IBM Security Access Manager for Mobile 8.x before 8.0.1.4 IF3 and Security Access Manager 9.x before 9.0.1.0 IF5 do not properly restrict failed login attempts, which makes it easier for remote attackers to obtain access via a brute-force approach.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 67%
Affected Products (NVD)
VendorProductVersion
ibmsecurity_access_manager
9.0.0
ibmsecurity_access_manager
9.0.0.1
ibmsecurity_access_manager
9.0.1.0
ibmsecurity_access_manager_for_mobile
8.0.0.0
ibmsecurity_access_manager_for_mobile
8.0.0.1
ibmsecurity_access_manager_for_mobile
8.0.0.2
ibmsecurity_access_manager_for_mobile
8.0.0.3
ibmsecurity_access_manager_for_mobile
8.0.0.4
ibmsecurity_access_manager_for_mobile
8.0.0.5
ibmsecurity_access_manager_for_mobile
8.0.1
ibmsecurity_access_manager_for_mobile
8.0.1.2
ibmsecurity_access_manager_for_mobile
8.0.1.3
ibmsecurity_access_manager_for_mobile
8.0.1.4
𝑥
= Vulnerable software versions
Common Weakness Enumeration