IBM Rational ClearQuest 7.0.1.1 and 7.0.0.2 generates different error messages depending on whether the username is valid or invalid, which allows remote attackers to enumerate usernames.
https://exchange.xforce.ibmcloud.com/vulnerabilities/41042
http://www.vupen.com/english/advisories/2008/0804/references
http://www.securitytracker.com/id?1019566
http://www.securityfocus.com/bid/28132