PT-2021-18514 · Ibm · Ibm Websphere Application Server+1
Kajetan Rostojek
·
Published
2021-09-16
·
Updated
2021-09-27
·
CVE-2021-29842
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM WebSphere Application Server versions 7.0 through 9.0
IBM WebSphere Application Server Liberty versions 17.0.0.3 through 21.0.0.9
Description
The issue allows a remote user to enumerate usernames due to a difference in responses from valid and invalid login attempts.
Recommendations
For IBM WebSphere Application Server versions 7.0 through 9.0, update to a version that includes a fix for this issue.
For IBM WebSphere Application Server Liberty versions 17.0.0.3 through 21.0.0.9, update to a version that includes a fix for this issue.
Fix
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Websphere Application Server
Ibm Websphere Application Server Liberty