First published: Mon Oct 18 2010(Updated: )
Dswsbobje in SAP BusinessObjects Enterprise XI 3.2 generates different error messages depending on whether the Login field corresponds to a valid username, which allows remote attackers to enumerate account names via a login SOAPAction to the dswsbobje/services/session URI.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP BusinessObjects | =3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3979 has a medium severity rating due to its potential for account enumeration.
To mitigate CVE-2010-3979, update to a patched version of SAP BusinessObjects that addresses this vulnerability.
CVE-2010-3979 exploits the way SAP BusinessObjects handles login requests, allowing attackers to enumerate usernames.
Yes, successful account enumeration from CVE-2010-3979 can facilitate further targeted attacks against valid accounts.
CVE-2010-3979 affects SAP BusinessObjects Enterprise XI version 3.2.