First published: Sat Apr 16 2005(Updated: )
The POP3 server in IBM iSeries AS/400 returns different error messages when the user exists or not, which allows remote attackers to determine valid user IDs on the server.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM iSeries AS/400 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1133 has a medium severity rating due to the potential for remote attackers to enumerate valid user IDs.
To fix CVE-2005-1133, implement measures to ensure that the POP3 server does not return different error messages for existing and non-existing users.
The potential impact of CVE-2005-1133 is the exposure of valid user IDs to attackers, which can lead to further attacks.
CVE-2005-1133 affects the IBM iSeries AS/400 systems that run the vulnerable POP3 server.
CVE-2005-1133 remains a concern as legacy systems may still be in use and vulnerable to exploitation.