IBM Tivoli Provisioning Manager Express provides unspecified information in error messages when (1) attempted duplication of a username occurs when creating an account or (2) when trying to login using a valid username, which makes it easier for remote attackers to enumerate usernames.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/484607/100/0/threaded | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/38866 | vdb entry |
http://securityreason.com/securityalert/3458 | third party advisory |
http://www.securityfocus.com/bid/26724 | vdb entry |