No advisories yet.
Solution
None
Workaround
Implement the LDAP user registry in place of the database-managed custom user registry provided in Log Analysis. Refer to the link below for more information: * Configuring LDAP authentication in IBM Operations Analytics for Log Analysis 1.3.7 https://www.ibm.com/docs/en/oala/1.3.7 * Configuring LDAP authentication in IBM Operations Analytics for Log Analysis 1.3.8 https://www.ibm.com/docs/en/oala/1.3.8
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7268536 |
|
Wed, 27 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 27 May 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4 IBM SmartCloud Analytics - Log Analysis does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. | |
| Title | IBM Operations Analytics - Log Analysis is affected by Weak Password Policy and Inadequate Account Lockout Mechanism | |
| First Time appeared |
Ibm
Ibm operations Analytics Log Analysis |
|
| Weaknesses | CWE-521 | |
| CPEs | cpe:2.3:a:ibm:operations_analytics___log_analysis:1.3.5.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:operations_analytics___log_analysis:1.3.6.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:operations_analytics___log_analysis:1.3.7.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:operations_analytics___log_analysis:1.3.8.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm operations Analytics Log Analysis |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-05-27T15:33:16.940Z
Reserved: 2024-07-08T19:30:52.530Z
Link: CVE-2024-40684
Updated: 2026-05-27T15:33:13.786Z
Status : Awaiting Analysis
Published: 2026-05-27T14:16:40.757
Modified: 2026-05-27T14:53:51.833
Link: CVE-2024-40684
No data.
OpenCVE Enrichment
Updated: 2026-05-27T15:30:27Z