Username Enumeration Vulnerability in Sun Java System Identity Manager
CVE-2009-1076
Currently unrated
Summary
The Sun Java System Identity Manager versions 7.0 through 8.0 exhibit inconsistent responses when an end-user question-based login fails. This discrepancy can be exploited by remote attackers to determine the validity of usernames. By testing various usernames, attackers can identify which accounts exist within the system, potentially leading to unauthorized access or further exploitation of user accounts.
References
Timeline
Vulnerability Reserved
Vulnerability published