First published: Thu Jan 29 2009(Updated: )
The login module in Sun Java System Access Manager 6 2005Q1 (aka 6.3), 7 2005Q4 (aka 7.0), and 7.1 responds differently to a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun Java System Access Manager | =6.3_2005q1 | |
Sun Java System Access Manager | =6.3_2005q1 | |
Sun Java System Access Manager | =6.3_2005q1 | |
Sun Java System Access Manager | =7.1 | |
Sun Java System Access Manager | =7_2005q4 | |
Sun Java System Access Manager | =7_2005q4 | |
Sun Java System Access Manager | =6.3_2005q1 | |
Sun Java System Access Manager | =7.1 | |
Sun Java System Access Manager | =7.1 | |
Sun Java System Access Manager | =6.3_2005q1 | |
Sun Java System Access Manager | =7.1 | |
Sun Java System Access Manager | =6.3_2005q1 | |
Sun Java System Access Manager | =6.3_2005q1 | |
Sun Java System Access Manager | =7.1 | |
Sun Java System Access Manager | =7_2005q4 | |
Sun Java System Access Manager | =7.1 | |
Sun Java System Access Manager | =7_2005q4 | |
Sun Java System Access Manager | =7.1 | |
Sun Java System Access Manager | =7.1 | |
Sun Java System Access Manager | =6.3_2005q1 | |
Sun Java System Access Manager | =7_2005q4 | |
Sun Java System Access Manager | =7.1 | |
Sun Java System Access Manager | =7.1 | |
Sun Java System Access Manager | =7_2005q4 | |
Sun Java System Access Manager | =7_2005q4 | |
Sun Java System Access Manager | =6.3_2005q1 | |
Sun Java System Access Manager | =6.3_2005q1 | |
Sun Java System Access Manager | =6.3_2005q1 | |
Sun Java System Access Manager | =7.1 | |
Sun Java System Access Manager | =6.3_2005q1 | |
Sun Java System Access Manager | =7_2005q4 | |
Sun Java System Access Manager | =7_2005q4 | |
Sun Java System Access Manager | =7_2005q4 | |
Sun Java System Access Manager | =7.1 | |
Sun Java System Access Manager | =7_2005q4 | |
Sun Java System Access Manager | =7_2005q4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.