PT-2013-5927 · Tyler Technologies · Taxweb
Published
2013-10-28
·
Updated
2013-11-21
·
CVE-2013-6020
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Tyler Technologies TaxWeb version 3.13.3.1
Description
The issue allows remote attackers to enumerate account names by sending a series of requests to certain applications and analyzing the different HTTP status codes returned for invalid password-recovery requests, depending on whether the user account exists. This can be done via requests to the Assessor, Recorder, or Treasurer application.
Recommendations
For Tyler Technologies TaxWeb version 3.13.3.1, consider restricting access to the passwordRequestPOST.jsp page until a fix is available, or apply configuration changes to prevent differentiation in HTTP status codes for invalid password-recovery requests. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Taxweb