PT-2026-29529 · Sage Dpw · Sage Dpw
Published
2026-04-01
·
Updated
2026-04-01
·
CVE-2025-67806
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Sage DPW versions prior to 2021 06 000
Description
The login mechanism exhibits different responses for valid and invalid usernames, potentially allowing the enumeration of existing accounts. On-premise administrators can disable this behavior in newer versions.
Recommendations
Update to version 2021 06 000 or later.
Fix
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sage Dpw