Computrols CBAS 18.0.0 allows Username Enumeration.
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.
Link | Tags |
---|---|
https://applied-risk.com/labs/advisories | third party advisory |
https://applied-risk.com/index.php/download_file/view/196/165 | third party advisory |
http://packetstormsecurity.com/files/155266/Computrols-CBAS-Web-19.0.0-Username-Enumeration.html |