Authentication Error Disclosure in Helix ALM by Perforce
CVE-2024-11084

6.3MEDIUM

Key Information:

Vendor

Perforce

Status
Vendor
CVE Published:
15 April 2025

What is CVE-2024-11084?

Helix ALM prior to version 2025.1 has a security flaw that allows attackers to discern the existence of usernames based on distinct error messages received during the authentication process. This vulnerability can be exploited to facilitate further attacks by revealing sensitive user information. Organizations using affected versions should prioritize upgrading to secure their authentication mechanisms and prevent potential unauthorized access.

Affected Version(s)

Helix ALM 0 < 2025.1

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.