IBM Security Access Manager for Mobile 8.x before 8.0.1.4 IF3 and Security Access Manager 9.x before 9.0.1.0 IF5 do not properly restrict failed login attempts, which makes it easier for remote attackers to obtain access via a brute-force approach.
Software security is not security software. Here we're concerned with topics like authentication, access control, confidentiality, cryptography, and privilege management.
Link | Tags |
---|---|
http://www-01.ibm.com/support/docview.wss?uid=swg1IV89258 | vendor advisory broken link |
http://www-01.ibm.com/support/docview.wss?uid=swg1IV89240 | vendor advisory broken link |
http://www.securityfocus.com/bid/93178 | vdb entry |
http://www-01.ibm.com/support/docview.wss?uid=swg21991107 | vendor advisory |