First published: Mon Feb 19 2024(Updated: )
IBM Common Licensing 9.0 could allow a local user to enumerate usernames due to an observable response discrepancy. IBM X-Force ID: 273337.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM IBM® Engineering Requirements Management DOORS | <=9.7.2.7 | |
IBM IBM® Engineering Requirements Management DOORS Web Access | <=9.7.2.7 | |
IBM Common Licensing | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-50306 has a medium severity level due to its potential for local user username enumeration.
To fix CVE-2023-50306, update IBM® Engineering Requirements Management DOORS and IBM® Engineering Requirements Management DOORS Web Access to the latest version.
CVE-2023-50306 affects local users of IBM® Engineering Requirements Management DOORS and IBM® Engineering Requirements Management DOORS Web Access versions up to 9.7.2.7.
CVE-2023-50306 is a vulnerability that allows local users to enumerate usernames due to an observable response discrepancy.
CVE-2023-50306 was disclosed in 2023 as part of IBM's security updates.