Username Enumeration Vulnerability in Sun Java System Access Manager
CVE-2009-0348

Currently unrated

Key Information:

Vendor
Oracle
Vendor
CVE Published:
29 January 2009

Summary

The login module in specific versions of Sun Java System Access Manager exhibits a security flaw that allows remote attackers to distinguish between valid and invalid usernames based on differing responses to failed login attempts. This vulnerability can lead to unauthorized information disclosure and facilitate further attacks by providing a basis for unauthorized account access.

References

EPSS Score

8% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.