User Enumeration Vulnerability in Sun Java System Identity Manager
CVE-2009-1075
Currently unrated
Summary
The Sun Java System Identity Manager versions 7.0 to 8.0 contains a vulnerability that allows remote attackers to determine valid usernames via the 'Forgot Password' feature. This occurs because the application provides differing responses based on the existence of the account, thereby enabling attackers to exploit this behavior to enumerate valid usernames. Proper handling of user input and consistent response messages is essential to mitigate such vulnerabilities.
References
Timeline
Vulnerability Reserved
Vulnerability published