User Enumeration Vulnerability in Sun Java System Identity Manager
CVE-2009-1075

Currently unrated

Key Information:

Vendor
Oracle
Vendor
CVE Published:
25 March 2009

Summary

The Sun Java System Identity Manager versions 7.0 to 8.0 contains a vulnerability that allows remote attackers to determine valid usernames via the 'Forgot Password' feature. This occurs because the application provides differing responses based on the existence of the account, thereby enabling attackers to exploit this behavior to enumerate valid usernames. Proper handling of user input and consistent response messages is essential to mitigate such vulnerabilities.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.