CVE-2016-5997
medium
CVSS v3
6.5
CVSS v2
4.0
VIR risk
6.5
Description
The web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224_9.0.2A FP3 does not apply password-quality rules to password changes, which makes it easier for remote attackers to obtain access via a brute-force attack.
Predictions
Exploit likelihood
75%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg21990216
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| ibm | tealeaf_customer_experience | {"endIncluding":"8.7"} | |
| ibm | tealeaf_customer_experience | 8.8 | |
| ibm | tealeaf_customer_experience | 9.0.0 | |
| ibm | tealeaf_customer_experience | 9.0.1 | |
| ibm | tealeaf_customer_experience | 9.0.1a | |
| ibm | tealeaf_customer_experience | 9.0.2 | |
| ibm | tealeaf_customer_experience | 9.0.2a | |
References
CWEs
CWE-640
Verify integrity in audit chain (admin only). AS-IS.