PT-2013-5927 · Tyler Technologies · Taxweb
Publicado
2013-10-28
·
Atualizado
2013-11-21
·
CVE-2013-6020
CVSS v2.0
5.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Tyler Technologies TaxWeb version 3.13.3.1
Description
The issue allows remote attackers to enumerate account names by sending a series of requests to certain applications and analyzing the different HTTP status codes returned for invalid password-recovery requests, depending on whether the user account exists. This can be done via requests to the Assessor, Recorder, or Treasurer application.
Recommendations
For Tyler Technologies TaxWeb version 3.13.3.1, consider restricting access to the passwordRequestPOST.jsp page until a fix is available, or apply configuration changes to prevent differentiation in HTTP status codes for invalid password-recovery requests. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Taxweb