CVE-2014-6092
Severity CVSS v4.0:
Pending analysis
Type:
CWE-17
Code Errors
Publication date:
27/04/2015
Last modified:
12/04/2025
Description
IBM Curam Social Program Management (SPM) 5.2 before SP6 EP6, 6.0 SP2 before EP26, 6.0.4 before 6.0.4.6, and 6.0.5 before 6.0.5.6 requires failed-login handling for web-service accounts to have the same lockout policy as for standard user accounts, which makes it easier for remote attackers to cause a denial of service (web-service outage) by making many login attempts with a valid caseworker account name.
Impact
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:ibm:curam_social_program_management:*:sp6:*:*:*:*:*:* | 5.2 (including) | |
| cpe:2.3:a:ibm:curam_social_program_management:6.0.4.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:curam_social_program_management:6.0.4.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:curam_social_program_management:6.0.4.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:curam_social_program_management:6.0.4.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:curam_social_program_management:6.0.4.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:curam_social_program_management:6.0.4.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:curam_social_program_management:6.0.5.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:curam_social_program_management:6.0.5.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:curam_social_program_management:6.0.5.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:curam_social_program_management:6.0.5.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:curam_social_program_management:6.0.5.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:curam_social_program_management:6.0.5.5:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



