First published: Thu Apr 16 2009(Updated: )
The web login functionality (c/portal/login) in Novell Teaming 1.0 through SP3 (1.0.3) generates different error messages depending on whether the username is valid or invalid, which makes it easier for remote attackers to enumerate usernames.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell Teaming | =1.0.2 | |
Novell Teaming | =1.0-sp3 | |
Novell Teaming | =1.0-sp2 | |
Novell Teaming | =1.0.1 | |
Novell Teaming | =1.0.3 | |
Novell Teaming | =1.0 | |
Novell Teaming | =1.0-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-1293 is considered a moderate severity vulnerability due to its potential for facilitating username enumeration.
To address CVE-2009-1293, it is recommended to upgrade Novell Teaming to a version that resolve the enumeration of usernames.
CVE-2009-1293 affects Novell Teaming versions 1.0 through SP3 (1.0.3) including all intermediary versions like 1.0.1, 1.0.2, and 1.0-sp1.
CVE-2009-1293 allows remote attackers to perform username enumeration due to varied error messages returned during login attempts.
CVE-2009-1293 does not compromise user data directly but increases the risk of targeted attacks through account enumeration.