CVE-2016-5997
Last modified
CVE-2016-5997 is a vulnerability of currently unknown severity. The web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224_9.0.2A FP3 does not apply password-quality rules to password changes, which makes it easier for remote attackers to obtain access via a brute-force attack.. EPSS estimates a 0.82% chance of exploitation in the next 30 days.
Description
The web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224_9.0.2A FP3 does not apply password-quality rules to password changes, which makes it easier for remote attackers to obtain access via a brute-force attack.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Tealeaf Customer Experience | <= 8.7 |
| Ibm | Tealeaf Customer Experience | 8.8 |
| Ibm | Tealeaf Customer Experience | 9.0.0 |
| Ibm | Tealeaf Customer Experience | 9.0.1 |
| Ibm | Tealeaf Customer Experience | 9.0.1a |
| Ibm | Tealeaf Customer Experience | 9.0.2 |
| Ibm | Tealeaf Customer Experience | 9.0.2a |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-5997?
How severe is CVE-2016-5997?
How do I fix CVE-2016-5997?
Are you affected by CVE-2016-5997?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
