Vulnerabilities > CVE-2021-38890 - Improper Restriction of Excessive Authentication Attempts vulnerability in IBM Sterling Connect:Direct
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
IBM Sterling Connect:Direct Web Services 1.0 and 6.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 209507.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 12 | |
OS | 1 | |
OS | 1 | |
OS | 1 | |
OS | 1 |