Total vulnerabilities in the database
Sun Java System Identity Manager (IdM) 7.0 through 8.0 responds differently to failed use of the end-user question-based login feature depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.
Software | From | Fixed in |
---|---|---|
sun / java_system_identity_manager | 7.1.1 | 7.1.1.x |
sun / java_system_identity_manager | 7.0 | 7.0.x |
sun / java_system_identity_manager | 7.1 | 7.1.x |
sun / java_system_identity_manager | 8.0 | 8.0.x |