CVE-2009-1293: Infoleak
The web login functionality (c/portal/login) in Novell Teaming 1.0 through SP3 (1.0.3) generates different error messages depending on whether the username is valid or invalid, which makes it easier for remote attackers to enumerate usernames.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1293?
CVE-2009-1293 is considered a moderate severity vulnerability due to its potential for facilitating username enumeration.
How do I fix CVE-2009-1293?
To address CVE-2009-1293, it is recommended to upgrade Novell Teaming to a version that resolve the enumeration of usernames.
What versions of Novell Teaming are affected by CVE-2009-1293?
CVE-2009-1293 affects Novell Teaming versions 1.0 through SP3 (1.0.3) including all intermediary versions like 1.0.1, 1.0.2, and 1.0-sp1.
What does CVE-2009-1293 vulnerability entail?
CVE-2009-1293 allows remote attackers to perform username enumeration due to varied error messages returned during login attempts.
Is user data compromised due to CVE-2009-1293?
CVE-2009-1293 does not compromise user data directly but increases the risk of targeted attacks through account enumeration.