CVE-2016-5964: IBM Security Privileged Identity Manager

Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.

IBM Security Privileged Identity Manager Virtual Appliance version 2.0.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.

Affected products

  • IBM Security Privileged Identity Manager: version 2.0.2 only

Published 2017-02-01. Last modified 2026-06-17.