CVE-2013-3040 Information

Description

IBM InfoSphere Information Server through 8.5 FP3 8.7 through FP2 and 9.1 produces login-failure messages indicating whether the username or password is incorrect which allows remote attackers to enumerate user accounts via a brute-force attack.

Reference

http://www.securityfocus.com/bid/61755 http://www-01.ibm.com/support/docview.wss?uid=swg21646136 https://exchange.xforce.ibmcloud.com/vulnerabilities/84765

Share on: