Username Enumeration Vulnerability in SAP BusinessObjects by SAP
CVE-2014-8309
Currently unrated
Key Information:
- Vendor
- SAP
- Vendor
- CVE Published:
- 16 October 2014
Summary
SAP BusinessObjects versions 4.0 and XI (R2 and 3.1) contain a vulnerability that allows attackers to exploit timing discrepancies in error messages produced during failed authentication attempts. When users try to log in with invalid credentials, the system responds with varying timing delays based on whether the account exists. This discrepancy can be leveraged by remote attackers to deduce valid usernames by monitoring the timing of responses, providing a pathway for further attacks on this authentication mechanism.
References
Timeline
Vulnerability published
Vulnerability Reserved