Problem:
If a user is a "Real Nimbus User" (e.g. built-in administrator or non-account user) then you can log into CABI with their normal UIM user/password combination, by putting "UIM" in the "Organization" field.
if this does not work, you will need to log in as "superuser" to CABI, then locate the user in question, and set a password for the user that is identical to their UIM password.
Otherwise users will not be able to log in directly. Account Contact users and LDAP users are unable to log in directly and must go through UMP.
This occurs because although the users are synced from UIM to CABI the passwords are not, and the authentication is handled internally by the cabi or cabi_external probes. It is intentional - users are not intended to be logging into UIM CABI directly.