Computer Associates Unicenter Management Portal Username Disclosure Vulnerability
BID:11229
Info
Computer Associates Unicenter Management Portal Username Disclosure Vulnerability
| Bugtraq ID: | 11229 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 21 2004 12:00AM |
| Updated: | Sep 21 2004 12:00AM |
| Credit: | Discovery is credited to Thomas Adams <[email protected]>. |
| Vulnerable: |
Computer Associates Unicenter Management Portal 3.1 Computer Associates Unicenter Management Portal 2.0 |
| Not Vulnerable: | |
Discussion
Computer Associates Unicenter Management Portal Username Disclosure Vulnerability
Computer Associates Unicenter Management Portal has been reported vulnerable to an issue that may reveal valid usernames to an unauthenticated user. The vulnerability exists in the "Forgot your Password?" link on the management portal interface.
Computer Associates Unicenter Management Portal has been reported vulnerable to an issue that may reveal valid usernames to an unauthenticated user. The vulnerability exists in the "Forgot your Password?" link on the management portal interface.
Exploit / POC
Computer Associates Unicenter Management Portal Username Disclosure Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
Computer Associates Unicenter Management Portal Username Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Computer Associates Unicenter Management Portal Username Disclosure Vulnerability
References:
References:
- Unicenter Management Portal (Computer Associates)
- CA UniCenter Management Portal Username Enumeration Vulnerability (thomas adams
)