Username Enumeration Vulnerability in IBM Security Secret Server
CVE-2021-20569

5.3MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
14 September 2021

Summary

IBM Security Secret Server versions up to 11.0 are susceptible to a vulnerability that allows attackers to enumerate valid usernames. This issue arises from improper input validation, which can be exploited to gain insights into user identities, potentially leading to further attacks. Ensuring proper security measures and patching is critical to mitigate the risks associated with this vulnerability.

Affected Version(s)

Security Secret Server 10.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.