IBM Security Identity Governance and Intelligence 5.2.6 could allow an attacker to enumerate usernames to find valid login credentials which could be used to attempt further attacks against the system. IBM X-Force ID: 175336.
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.
Link | Tags |
---|---|
https://www.ibm.com/support/pages/node/6207906 | patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/175336 | vdb entry vendor advisory |