Vulnerability Bulletins |
IBM Security Bulletin: IBM Cúram Social Program Management when not configured with LDAP or SSO may be vulnerable to denial of service.(CVE-2014-6092). |
|
| Affected software | IBM |
|
Default authentication methods in IBM Curam Social Program Management do not allow for a per user account lockout policy, and rather employ a single, system wide policy. For most users of the system, a low lockout threshold is desirable. However, for users used to integrate with another system, such as a user whose sole purpose is to allow another system to invoke a particular web service, a low threshold for lockout may allow an attacker to lock out the other system, thereby effecting a denial More info: https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_c%25C3%25BAram_social_program_management_when_not_configured_with_ldap_or_sso_may_be_vulnerable_to_denial_of_service_cve_2014_6092?lang=en_us |
|






