Impact
The vulnerability in IBM Operations Analytics – Log Analysis allows attackers to compromise accounts because the software does not enforce strong password policies by default. This weakness (CWE‑521) means that weak or guessable passwords can be used to log in, giving attackers full access to the application and underlying data, potentially exposing sensitive information and compromising system integrity and availability.
Affected Systems
Affected versions are IBM Operations Analytics – Log Analysis 1.3.5.0 through 1.3.8.4. The vulnerability applies to the local user registry stored in the database; all installations using these releases are susceptible.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting no current exploitation activity. The likely attack vector is through the application’s login interface: an attacker can use a weak password to authenticate and gain unauthorized access. Because no patch is available, the risk remains unless mitigated.
OpenCVE Enrichment