CVE-2007-0310: Medium severity BMC Remedy Action Request System vulnerability
Published Jan 18, 2007
·Updated
BMC Remedy Action Request System 5.01.02 Patch 1267 generates different error messages for failed login attempts with a valid username than for those with an invalid username, which allows remote attackers to determine valid account names.
Affected Software
1 affected component
BMC Remedy Action Request System=5.01.02_patch_1267
Event History
Jan 18, 2007
CVE Published
12:28 AM
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-0310?
CVE-2007-0310 has a medium severity level as it can be exploited to determine valid usernames.
2
How do I fix CVE-2007-0310?
To fix CVE-2007-0310, update BMC Remedy Action Request System to a version that does not disclose different error messages for valid and invalid usernames.
3
What type of vulnerability is CVE-2007-0310?
CVE-2007-0310 is an information disclosure vulnerability.
4
Which software versions are affected by CVE-2007-0310?
CVE-2007-0310 affects BMC Remedy Action Request System version 5.01.02 Patch 1267.
5
Can CVE-2007-0310 lead to further attacks?
Yes, CVE-2007-0310 can lead to further attacks as it allows attackers to enumerate valid usernames.