IBM Lotus Sametime Username Enumeration Weakness
BID:35614
Info
IBM Lotus Sametime Username Enumeration Weakness
| Bugtraq ID: | 35614 |
| Class: | Design Error |
| CVE: |
CVE-2009-2435 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 09 2009 12:00AM |
| Updated: | Apr 13 2015 09:09PM |
| Credit: | Karan Khosla from Sense of Security Labs |
| Vulnerable: |
IBM Lotus Instant Messaging and Web Conferencing 6.5.1 |
| Not Vulnerable: | |
Discussion
IBM Lotus Sametime Username Enumeration Weakness
IBM Lotus Sametime is prone to a username-enumeration weakness because it responds differently to login attempts, depending on whether or not the username exists.
Attackers may exploit this weakness to discern valid usernames, which may aid them in brute-force password cracking or other attacks.
IBM Lotus Sametime 6.5.1 is vulnerable.
IBM Lotus Sametime is prone to a username-enumeration weakness because it responds differently to login attempts, depending on whether or not the username exists.
Attackers may exploit this weakness to discern valid usernames, which may aid them in brute-force password cracking or other attacks.
IBM Lotus Sametime 6.5.1 is vulnerable.
Exploit / POC
IBM Lotus Sametime Username Enumeration Weakness
Attackers can use readily available tools to exploit this issue.
Attackers can use readily available tools to exploit this issue.
Solution / Fix
IBM Lotus Sametime Username Enumeration Weakness
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
IBM Lotus Sametime Username Enumeration Weakness
References:
References:
- IBM Homepage (IBM)
- Lotus Sametime User Enumeration Vulnerability - Security Advisory �?? SOS-09- 004 (Sense of Security)