PT-2013-5927 · Tyler Technologies · Taxweb

Published

2013-10-28

·

Updated

2013-11-21

·

CVE-2013-6020

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Tyler Technologies TaxWeb version 3.13.3.1
Description The issue allows remote attackers to enumerate account names by sending a series of requests to certain applications and analyzing the different HTTP status codes returned for invalid password-recovery requests, depending on whether the user account exists. This can be done via requests to the Assessor, Recorder, or Treasurer application.
Recommendations For Tyler Technologies TaxWeb version 3.13.3.1, consider restricting access to the passwordRequestPOST.jsp page until a fix is available, or apply configuration changes to prevent differentiation in HTTP status codes for invalid password-recovery requests. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-6020

Affected Products

Taxweb