IBM Rational ClearQuest 7.0.1.1 and 7.0.0.2 generates different error messages depending on whether the username is valid or invalid, which allows remote attackers to enumerate usernames.
Weaknesses in this category are typically introduced during the configuration of the software.
Link | Tags |
---|---|
http://www.securitytracker.com/id?1019566 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/41042 | vdb entry |
http://secunia.com/advisories/29280 | patch vendor advisory third party advisory |
http://www-1.ibm.com/support/docview.wss?uid=swg1PK55561 | patch vendor advisory |
http://www.securityfocus.com/bid/28132 | patch vdb entry |
http://www.vupen.com/english/advisories/2008/0804/references | vdb entry vendor advisory |