PT-2013-5927 · Tyler Technologies · Taxweb

Publicado

2013-10-28

·

Atualizado

2013-11-21

·

CVE-2013-6020

CVSS v2.0

5.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Tyler Technologies TaxWeb version 3.13.3.1
Description The issue allows remote attackers to enumerate account names by sending a series of requests to certain applications and analyzing the different HTTP status codes returned for invalid password-recovery requests, depending on whether the user account exists. This can be done via requests to the Assessor, Recorder, or Treasurer application.
Recommendations For Tyler Technologies TaxWeb version 3.13.3.1, consider restricting access to the passwordRequestPOST.jsp page until a fix is available, or apply configuration changes to prevent differentiation in HTTP status codes for invalid password-recovery requests. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-6020

Produtos afetados

Taxweb