Vulnerability Name: | CCN-23679 | ||||||
Published: | 2005-12-15 | ||||||
Updated: | 2005-12-15 | ||||||
Summary: | IBM WebSphere Application Server could allow a remote attacker to obtain sensitive information. IBM WebSphere Application Server displays different response messages for valid or invalid usernames. An attacker could use brute force methods to determine valid account names on the server. | ||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||
CVSS v2 Severity: | 5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||
Vulnerability Consequences: | Obtain Information | ||||||
References: | Source: CCN Type: IBM WebSphere Application Server Web page Application Servers > WebSphere Application Server > WebSphere Application Server Source: CCN Type: Ioannis Web site IBM WEBSPHERE 6 Sample scripts Cross site scripting Source: XF Type: UNKNOWN websphere-usernames-obtain-information(23679) | ||||||
Vulnerable Configuration: | Configuration CCN 1:![]() | ||||||
BACK |