VulnerabilityModified
CVE-2009-1075
Sun Java System Identity Manager (IdM) 7.0 through 8.0 responds differently to failed use of the Forgot Password feature depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.
MEDIUM 5.0EPSS 2.46%
Does this matter?
Lower severity and a low EPSS score (2.46%). Track it; it rarely justifies an emergency change on its own.
Description
Sun Java System Identity Manager (IdM) 7.0 through 8.0 responds differently to failed use of the Forgot Password feature depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.46% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-255
- Affected
- sun/java system identity manager
- Source
- cve@mitre.org
References
- http://blogs.sun.com/security/entry/sun_alert_253267_sun_javaPatch, Vendor Advisory
- http://secunia.com/advisories/34380Vendor Advisory
- http://securitytracker.com/id?1021881
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-140936-01-1Patch
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-253267-1Patch, Vendor Advisory
- http://www.securityfocus.com/bid/34191Exploit, Patch
- http://www.vupen.com/english/advisories/2009/0797Vendor Advisory
- http://blogs.sun.com/security/entry/sun_alert_253267_sun_javaPatch, Vendor Advisory
- http://secunia.com/advisories/34380Vendor Advisory
- http://securitytracker.com/id?1021881
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-140936-01-1Patch
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-253267-1Patch, Vendor Advisory
- http://www.securityfocus.com/bid/34191Exploit, Patch
- http://www.vupen.com/english/advisories/2009/0797Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.