CVE-2026-7365 Details
Description
IBM Operations Analytics - Log Analysis and IBM SmartCloud Analytics - Log Analysis uses default passwords default passwords from the manufacturing process for use during the installation process, which could allow an attacker to bypass authentication.
A vulnerability exists in IBM Operations Analytics - Log Analysis and IBM SmartCloud Analytics - Log Analysis due to the use of default passwords from the manufacturing process, which are not required to be changed after installation. This flaw could enable an attacker to bypass authentication. The vulnerability affects versions 1.3.2.0, 1.3.3.0, 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.6.2, 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, and 1.3.8.4 on Linux.
Users are advised to reset the default password through the GUI or integrate IBM Operations Analytics - Log Analysis with LDAP. Instructions for updating default passwords during installation are available on the IBM Support website. For versions prior to 1.3.7.0, users should upgrade to 1.3.7-TIV-IOALA-FP_signed or later before applying the password reset.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ibm.com/support/pages/node/7272268 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-1392 | Use of Default Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ibm operations analytics log analysis | 1.3.2.0 1.3.3.0 1.3.5.0 1.3.5.1 1.3.5.2 1.3.5.3 1.3.6.0 1.3.6.1 1.3.7.0 1.3.7.1 1.3.7.2 1.3.8.0 1.3.8.1 1.3.8.2 1.3.8.3 1.3.8.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 2, 2026 | Initial Analysis | [email protected] |
| May 27, 2026 | New CVE Received | [email protected] |