The Sametime server in IBM Lotus Instant Messaging and Web Conferencing 6.5.1 generates error messages for a failed logon attempt with different time delays depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
http://www.senseofsecurity.com.au/advisories/SOS-09-004.pdf | url repurposed |
http://www.securityfocus.com/bid/35614 | vdb entry |