VYPR
Unrated severityNVD Advisory· Published Aug 16, 2013· Updated Apr 29, 2026

CVE-2013-3040

CVE-2013-3040

Description

IBM InfoSphere Information Server through 8.5 FP3, 8.7 through FP2, and 9.1 produces login-failure messages indicating whether the username or password is incorrect, which allows remote attackers to enumerate user accounts via a brute-force attack.

Affected products

8
  • cpe:2.3:a:ibm:infosphere_information_server:8.5:*:*:*:*:*:*:*+ 7 more
    • cpe:2.3:a:ibm:infosphere_information_server:8.5:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:infosphere_information_server:8.5.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:infosphere_information_server:8.5.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:infosphere_information_server:8.5.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:infosphere_information_server:8.7:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:infosphere_information_server:8.7.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:infosphere_information_server:8.7.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:infosphere_information_server:9.1:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.