PT-2025-16354 · Perforce · Helix Alm

Published

2025-04-15

·

Updated

2025-04-15

·

CVE-2024-11084

CVSS v4.0

6.3

Medium

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Helix ALM versions prior to 2025.1
Description The issue allows an attacker to determine whether a username exists due to distinct error responses during authentication.
Recommendations For versions prior to 2025.1, update to version 2025.1 or later to resolve the issue.

Fix

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-11084

Affected Products

Helix Alm