VulnerabilityModified
CVE-2009-1769
The web interface in Open Computer and Software Inventory Next Generation (OCS Inventory NG) 1.01 generates different error messages depending on whether a username is valid, which allows remote attackers to enumerate valid usernames.
MEDIUM 5.0EPSS 1.56%
Does this matter?
Lower severity and a low EPSS score (1.56%). Track it; it rarely justifies an emergency change on its own.
Description
The web interface in Open Computer and Software Inventory Next Generation (OCS Inventory NG) 1.01 generates different error messages depending on whether a username is valid, which allows remote attackers to enumerate valid usernames.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.56% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- ocsinventory-ng/ocs inventory ng
- Source
- cve@mitre.org
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=529344
- http://secunia.com/advisories/35157Vendor Advisory
- http://secunia.com/advisories/35313Vendor Advisory
- http://www.ocsinventory-ng.org/index.php?mact=News%2Ccntnt01%2Cdetail%2C0&cntnt01articleid=133&cntnt01returnid=69
- http://www.securityfocus.com/bid/35023
- https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00050.html
- https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00057.html
- https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00063.html
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=529344
- http://secunia.com/advisories/35157Vendor Advisory
- http://secunia.com/advisories/35313Vendor Advisory
- http://www.ocsinventory-ng.org/index.php?mact=News%2Ccntnt01%2Cdetail%2C0&cntnt01articleid=133&cntnt01returnid=69
- http://www.securityfocus.com/bid/35023
- https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00050.html
- https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00057.html
- https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00063.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.