Executive brief
IBM Operations Analytics - Log Analysis, a tool used for monitoring and analyzing IT infrastructure logs, contains a security weakness in its default login settings. The system does not enforce strong password requirements or adequate account lockout protections, making it easier for unauthorized individuals to guess user credentials. If exploited, an attacker could gain access to sensitive log data and operational insights, potentially compromising the security of the monitored environment.
Technical details
IBM Operations Analytics - Log Analysis is vulnerable to improper authentication due to weak password requirements (CWE-521) and inadequate account lockout mechanisms in its Backend Authentication and Session Management module. The vulnerability exists when using the default database-managed custom user registry. While the attack complexity is rated as high, a remote attacker can exploit these weak defaults to perform brute-force or credential-guessing attacks to gain unauthorized access to user accounts. No official patch is currently available; however, IBM recommends migrating to an LDAP user registry to enforce more robust authentication policies.
Affected products
- IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4
Timeline
- 2026-04-03: advisory: Initial IBM security bulletin published
- 2026-05-27: disclosed: NVD publication date