Novell iChain 2.2 before Support Pack 1 uses a shorter timeout for a non-existent user than a valid user, which makes it easier for remote attackers to guess usernames and conduct brute force password guessing.
| Software | From | Fixed in |
|---|---|---|
| novell / ichain | 2.2 | 2.2.x |