OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) 7 generates different responses depending on whether or not a username is valid in a failed login attempt, which allows remote attackers to enumerate valid usernames.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/27210 | vdb entry exploit |
http://secunia.com/advisories/28410 | third party advisory |
http://www.securityfocus.com/archive/1/486009/100/0/threaded | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/39574 | vdb entry |