2025-04-09 02:05:49 +00:00

108 lines
3.2 KiB
JSON

{
"id": "CVE-2007-6408",
"sourceIdentifier": "cve@mitre.org",
"published": "2007-12-17T18:46:00.000",
"lastModified": "2025-04-09T00:30:58.490",
"vulnStatus": "Deferred",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "IBM Tivoli Provisioning Manager Express provides unspecified information in error messages when (1) attempted duplication of a username occurs when creating an account or (2) when trying to login using a valid username, which makes it easier for remote attackers to enumerate usernames."
},
{
"lang": "es",
"value": "IBM Tivoli Provisioning Manager Express proporciona informaci\u00f3n no especificada en mensajes de error cuando (1) se intenta duplicar un nombre de usuario al crear una cuenta \u00f3 (2) al introducir un nombre de usuario v\u00e1lido que facilita a atacantes remotos enumerar los nombre de usuario."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"baseScore": 5.0,
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 10.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:tivoli_provisioning_manager_express:*:*:*:*:*:*:*:*",
"matchCriteriaId": "5D0FD4F9-F807-4E09-9A0D-C67C3BA1129B"
}
]
}
]
}
],
"references": [
{
"url": "http://securityreason.com/securityalert/3458",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/484607/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/26724",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/38866",
"source": "cve@mitre.org"
},
{
"url": "http://securityreason.com/securityalert/3458",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/484607/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/26724",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/38866",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}