7.5
CVSSv3

CVE-2021-38890

CVSSv4: NA | CVSSv3: 7.5 | CVSSv2: 5 | VMScore: 850 | EPSS: 0.00186 | KEV: Not Included
Published: 23/11/2021 Updated: 21/11/2024

Vulnerability Summary

IBM Sterling Connect:Direct Web Services 1.0 and 6.0 uses an inadequate account lockout setting that could allow a remote malicious user to brute force account credentials. IBM X-Force ID: 209507.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ibm connect direct web services

ibm sterling connect direct