Unrated severityNVD Advisory· Published Aug 16, 2013· Updated Apr 29, 2026
CVE-2013-3040
CVE-2013-3040
Description
IBM InfoSphere Information Server through 8.5 FP3, 8.7 through FP2, and 9.1 produces login-failure messages indicating whether the username or password is incorrect, which allows remote attackers to enumerate user accounts via a brute-force attack.
Affected products
8cpe:2.3:a:ibm:infosphere_information_server:8.5:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:ibm:infosphere_information_server:8.5:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:infosphere_information_server:8.5.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:infosphere_information_server:8.5.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:infosphere_information_server:8.5.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:infosphere_information_server:8.7:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:infosphere_information_server:8.7.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:infosphere_information_server:8.7.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:infosphere_information_server:9.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www-01.ibm.com/support/docview.wssnvdPatchVendor Advisory
- www.securityfocus.com/bid/61755nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/84765nvd
News mentions
0No linked articles in our index yet.