Username Enumeration Vulnerability in Sun Java System Access Manager
CVE-2009-0348
Currently unrated
What is CVE-2009-0348?
The login module in specific versions of Sun Java System Access Manager exhibits a security flaw that allows remote attackers to distinguish between valid and invalid usernames based on differing responses to failed login attempts. This vulnerability can lead to unauthorized information disclosure and facilitate further attacks by providing a basis for unauthorized account access.