Username Enumeration Vulnerability in IBM Security Secret Server
CVE-2021-20569
5.3MEDIUM
Summary
IBM Security Secret Server versions up to 11.0 are susceptible to a vulnerability that allows attackers to enumerate valid usernames. This issue arises from improper input validation, which can be exploited to gain insights into user identities, potentially leading to further attacks. Ensuring proper security measures and patching is critical to mitigate the risks associated with this vulnerability.
Affected Version(s)
Security Secret Server 10.0
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved