IBM Security Identity Manager 7.0.2 could allow a remote user to enumerate usernames due to a difference of responses from valid and invalid login attempts. IBM X-Force ID: 200018
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.
Link | Tags |
---|---|
https://www.ibm.com/support/pages/node/6454605 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/200018 | vdb entry vendor advisory |