Description
IBM Curam Social Program Management (SPM) 5.2 before SP6 EP6, 6.0 SP2 before EP26, 6.0.4 before 6.0.4.6, and 6.0.5 before 6.0.5.6 requires failed-login handling for web-service accounts to have the same lockout policy as for standard user accounts, which makes it easier for remote attackers to cause a denial of service (web-service outage) by making many login attempts with a valid caseworker account name.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2014-5978 | IBM Curam Social Program Management (SPM) 5.2 before SP6 EP6, 6.0 SP2 before EP26, 6.0.4 before 6.0.4.6, and 6.0.5 before 6.0.5.6 requires failed-login handling for web-service accounts to have the same lockout policy as for standard user accounts, which makes it easier for remote attackers to cause a denial of service (web-service outage) by making many login attempts with a valid caseworker account name. |
References
| Link | Providers |
|---|---|
| http://www-01.ibm.com/support/docview.wss?uid=swg21697742 |
|
History
No history.
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2024-08-06T12:03:02.337Z
Reserved: 2014-09-02T00:00:00.000Z
Link: CVE-2014-6092
No data.
Status : Modified
Published: 2015-04-27T11:59:02.433
Modified: 2026-05-06T22:30:45.220
Link: CVE-2014-6092
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD