CVE-2019-15132: Medium severity zabbix vulnerability
Zabbix through 4.4.0alpha1 allows User Enumeration. With login requests, it is possible to enumerate application usernames based on the variability of server responses (e.g., the "Login name or password is incorrect" and "No permissions for system access" messages, or just blocking for a number of seconds). This affects both apijsonrpc.php and index.php.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-15132?
CVE-2019-15132 is a vulnerability in Zabbix through 4.4.0alpha1 that allows user enumeration.
How does CVE-2019-15132 allow user enumeration?
CVE-2019-15132 allows user enumeration by exploiting the variability of server responses to login requests.
What is the severity of CVE-2019-15132?
The severity of CVE-2019-15132 is medium, with a severity value of 5.3.
Which software versions are affected by CVE-2019-15132?
CVE-2019-15132 affects Zabbix versions 4.0.26, 4.4.0-alpha1, and 5.0.0 to 5.0.5, as well as Debian Linux 9.0.
How can I fix CVE-2019-15132?
To fix CVE-2019-15132, upgrade Zabbix to a version beyond 4.4.0alpha1 or apply the necessary patches.