Show plain JSON{"id": "CVE-2016-3025", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 5.0, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N", "authentication": "NONE", "integrityImpact": "NONE", "accessComplexity": "LOW", "availabilityImpact": "NONE", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV30": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.0", "baseScore": 8.1, "attackVector": "NETWORK", "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "HIGH", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 2.2}]}, "published": "2016-11-25T03:59:06.530", "references": [{"url": "http://www-01.ibm.com/support/docview.wss?uid=swg1IV89240", "tags": ["Broken Link"], "source": "psirt@us.ibm.com"}, {"url": "http://www-01.ibm.com/support/docview.wss?uid=swg1IV89258", "tags": ["Broken Link"], "source": "psirt@us.ibm.com"}, {"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21991107", "tags": ["Vendor Advisory"], "source": "psirt@us.ibm.com"}, {"url": "http://www.securityfocus.com/bid/93178", "source": "psirt@us.ibm.com"}, {"url": "http://www-01.ibm.com/support/docview.wss?uid=swg1IV89240", "tags": ["Broken Link"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www-01.ibm.com/support/docview.wss?uid=swg1IV89258", "tags": ["Broken Link"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21991107", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securityfocus.com/bid/93178", "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Deferred", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-254"}]}], "descriptions": [{"lang": "en", "value": "IBM Security Access Manager for Mobile 8.x before 8.0.1.4 IF3 and Security Access Manager 9.x before 9.0.1.0 IF5 do not properly restrict failed login attempts, which makes it easier for remote attackers to obtain access via a brute-force approach."}, {"lang": "es", "value": "IBM Security Access Manager para Mobile 8.x en versiones anteriores a 8.0.1.4 IF3 y Security Access Manager 9.x en versiones anteriores a 9.0.1.0 IF5 no restringe adecuadamente intentos de inicio de sesi\u00f3n fallidos, lo que facilita a atacantes remotos obtener acceso a trav\u00e9s de una aproximaci\u00f3n de fuerza bruta."}], "lastModified": "2025-04-12T10:46:40.837", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:ibm:security_access_manager:9.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F49FA0E2-5FEB-4831-980E-CFBE7E44277A"}, {"criteria": "cpe:2.3:a:ibm:security_access_manager:9.0.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A6B67748-2677-44E7-B43D-857EBCA926C2"}, {"criteria": "cpe:2.3:a:ibm:security_access_manager:9.0.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2AEE420D-4686-4C58-B77A-2E509983F4C3"}, {"criteria": "cpe:2.3:a:ibm:security_access_manager_for_mobile:8.0.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "44310E32-EA05-420B-8676-4E6EEAFB6631"}, {"criteria": "cpe:2.3:a:ibm:security_access_manager_for_mobile:8.0.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8B93CED0-E8FA-4238-8963-46074D11A334"}, {"criteria": "cpe:2.3:a:ibm:security_access_manager_for_mobile:8.0.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "907BB0CF-D270-4493-8D61-9841E6C5FE45"}, {"criteria": "cpe:2.3:a:ibm:security_access_manager_for_mobile:8.0.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E0801BD2-D95B-4703-9804-A555F9E7BA19"}, {"criteria": "cpe:2.3:a:ibm:security_access_manager_for_mobile:8.0.0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "525EF7EC-712E-4C84-A15C-B2A30BD11A01"}, {"criteria": "cpe:2.3:a:ibm:security_access_manager_for_mobile:8.0.0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2EE90667-0C16-4E4B-98DC-A6AD7A073D64"}, {"criteria": "cpe:2.3:a:ibm:security_access_manager_for_mobile:8.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AA8844A0-17D5-4EE9-85C4-518DACE7C9D0"}, {"criteria": "cpe:2.3:a:ibm:security_access_manager_for_mobile:8.0.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F0D646B2-7308-43A0-AE76-873946FB024E"}, {"criteria": "cpe:2.3:a:ibm:security_access_manager_for_mobile:8.0.1.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4B1988E5-DFE6-4282-B9D3-6655297B481B"}, {"criteria": "cpe:2.3:a:ibm:security_access_manager_for_mobile:8.0.1.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4BEF4063-73D7-416D-AD21-CDC1C0534677"}], "operator": "OR"}]}], "sourceIdentifier": "psirt@us.ibm.com"}