CVE-2024-11084: Potential Username Enumeration in Helix ALM
Published Apr 15, 2025
·Updated
Helix ALM prior to 2025.1 returns distinct error responses during authentication, allowing an attacker to determine whether a username exists.
Affected Software
1 affected component
Perforce Helix ALM<2025.1
Event History
Apr 15, 2025
CVE Published
via MITRE·03:34 PM
Data Sourced
via MITRE·03:34 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-11084?
CVE-2024-11084 is classified as a medium severity vulnerability.
2
How do I fix CVE-2024-11084?
To mitigate CVE-2024-11084, upgrade Helix ALM to version 2025.1 or later.
3
What does CVE-2024-11084 allow an attacker to do?
CVE-2024-11084 allows an attacker to determine the existence of a username through distinct error responses during authentication.
4
Which versions of Helix ALM are affected by CVE-2024-11084?
Helix ALM versions prior to 2025.1 are affected by CVE-2024-11084.
5
Is there a workaround for CVE-2024-11084?
There are no specific workarounds available for CVE-2024-11084 other than upgrading to a patched version.