First published: Thu Apr 16 2009(Updated: )
The web login functionality (c/portal/login) in Novell Teaming 1.0 through SP3 (1.0.3) generates different error messages depending on whether the username is valid or invalid, which makes it easier for remote attackers to enumerate usernames.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell Teaming | =1.0.2 | |
Novell Teaming | =1.0-sp3 | |
Novell Teaming | =1.0-sp2 | |
Novell Teaming | =1.0.1 | |
Novell Teaming | =1.0.3 | |
Novell Teaming | =1.0 | |
Novell Teaming | =1.0-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.