SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2012-5055

DaoAuthenticationProvider in VMware SpringSource Spring Security before 2.0.8, 3.0.x before 3.0.8, and 3.1.x before 3.1.3 does not check the password if the user is not found, which makes the response delay shorter and might allow remote attackers to…

MEDIUM 5.0EPSS 1.95%

Does this matter?

Lower severity and a low EPSS score (1.95%). Track it; it rarely justifies an emergency change on its own.

Description

DaoAuthenticationProvider in VMware SpringSource Spring Security before 2.0.8, 3.0.x before 3.0.8, and 3.1.x before 3.1.3 does not check the password if the user is not found, which makes the response delay shorter and might allow remote attackers to enumerate valid usernames via a series of login requests.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
1.95% probability · 79th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
vmware/springsource spring security
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.