CS&T CorporateTime for the Web returns different error messages for invalid usernames and invalid passwords, which allows remote attackers to determine valid usernames on the server.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/5529 | vdb entry |
http://www.securityfocus.com/archive/1/142672 | mailing list |
http://www.securityfocus.com/bid/1888 | vdb entry vendor advisory |