Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2qhq-448h-5333

Опубликовано: 28 авг. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.2

Описание

A vulnerability identified in NetIQ Advance Authentication that doesn't enforce account lockout when brute force attack is performed on API based login. This issue may lead to user account compromise if successful or may impact server performance. This issue impacts all NetIQ Advance Authentication before 6.3.5.1

A vulnerability identified in NetIQ Advance Authentication that doesn't enforce account lockout when brute force attack is performed on API based login. This issue may lead to user account compromise if successful or may impact server performance. This issue impacts all NetIQ Advance Authentication before 6.3.5.1

EPSS

Процентиль: 26%
0.00093
Низкий

8.2 High

CVSS3

Дефекты

CWE-307
CWE-667

Связанные уязвимости

CVSS3: 8.2
nvd
больше 1 года назад

A vulnerability identified in NetIQ Advance Authentication that doesn't enforce account lockout when brute force attack is performed on API based login. This issue may lead to user account compromise if successful or may impact server performance. This issue impacts all NetIQ Advance Authentication before 6.3.5.1

EPSS

Процентиль: 26%
0.00093
Низкий

8.2 High

CVSS3

Дефекты

CWE-307
CWE-667