CVE-2009-1076: Infoleak
Sun Java System Identity Manager (IdM) 7.0 through 8.0 responds differently to failed use of the end-user question-based login feature depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1076?
CVE-2009-1076 is classified as a medium severity vulnerability.
How does CVE-2009-1076 allow for username enumeration?
CVE-2009-1076 enables remote attackers to confirm the existence of user accounts based on the different responses for failed login attempts.
Which versions of Sun Java System Identity Manager are affected by CVE-2009-1076?
CVE-2009-1076 affects Sun Java System Identity Manager versions 7.0 through 8.0, specifically 7.0, 7.1, 7.1.1, and 8.0.
How can I mitigate CVE-2009-1076?
To mitigate CVE-2009-1076, it is recommended to upgrade to a patched version of Sun Java System Identity Manager.
What type of attack does CVE-2009-1076 facilitate?
CVE-2009-1076 facilitates an information disclosure attack allowing attackers to enumerate valid usernames.