Username Enumeration Vulnerability in Sun Java System Identity Manager
CVE-2009-1076

Currently unrated

Key Information:

Vendor
Oracle
Vendor
CVE Published:
25 March 2009

Summary

The Sun Java System Identity Manager versions 7.0 through 8.0 exhibit inconsistent responses when an end-user question-based login fails. This discrepancy can be exploited by remote attackers to determine the validity of usernames. By testing various usernames, attackers can identify which accounts exist within the system, potentially leading to unauthorized access or further exploitation of user accounts.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.