CVE-2010-3979: Infoleak
Dswsbobje in SAP BusinessObjects Enterprise XI 3.2 generates different error messages depending on whether the Login field corresponds to a valid username, which allows remote attackers to enumerate account names via a login SOAPAction to the dswsbobje/services/session URI.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3979?
CVE-2010-3979 has a medium severity rating due to its potential for account enumeration.
How do I fix CVE-2010-3979?
To mitigate CVE-2010-3979, update to a patched version of SAP BusinessObjects that addresses this vulnerability.
What does CVE-2010-3979 exploit?
CVE-2010-3979 exploits the way SAP BusinessObjects handles login requests, allowing attackers to enumerate usernames.
Can CVE-2010-3979 lead to further attacks?
Yes, successful account enumeration from CVE-2010-3979 can facilitate further targeted attacks against valid accounts.
What is affected by CVE-2010-3979?
CVE-2010-3979 affects SAP BusinessObjects Enterprise XI version 3.2.