The login module in Sun Java System Access Manager 6 2005Q1 (aka 6.3), 7 2005Q4 (aka 7.0), and 7.1 responds differently to a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.
http://secunia.com/advisories/33688
http://sunsolve.sun.com/search/document.do?assetkey=1-21-119465-15-1
http://sunsolve.sun.com/search/document.do?assetkey=1-66-242026-1
http://www.securityfocus.com/bid/33489
OR
cpe:2.3:a:sun:java_system_access_manager:6.3_2005q1:*:solaris_10_linux:*:*:*:*:*
cpe:2.3:a:sun:java_system_access_manager:6.3_2005q1:*:solaris_10_sparc:*:*:*:*:*
cpe:2.3:a:sun:java_system_access_manager:6.3_2005q1:*:solaris_10_windows:*:*:*:*:*
cpe:2.3:a:sun:java_system_access_manager:6.3_2005q1:*:solaris_10_x86:*:*:*:*:*
cpe:2.3:a:sun:java_system_access_manager:6.3_2005q1:*:solaris_8_linux:*:*:*:*:*
cpe:2.3:a:sun:java_system_access_manager:6.3_2005q1:*:solaris_8_sparc:*:*:*:*:*
cpe:2.3:a:sun:java_system_access_manager:6.3_2005q1:*:solaris_8_windows:*:*:*:*:*
cpe:2.3:a:sun:java_system_access_manager:6.3_2005q1:*:solaris_8_x86:*:*:*:*:*
cpe:2.3:a:sun:java_system_access_manager:6.3_2005q1:*:solaris_9_linux:*:*:*:*:*
cpe:2.3:a:sun:java_system_access_manager:6.3_2005q1:*:solaris_9_sparc:*:*:*:*:*
cpe:2.3:a:sun:java_system_access_manager:6.3_2005q1:*:solaris_9_windows:*:*:*:*:*
cpe:2.3:a:sun:java_system_access_manager:6.3_2005q1:*:solaris_9_x86:*:*:*:*:*
cpe:2.3:a:sun:java_system_access_manager:7.1:*:solaris_10_linux:*:*:*:*:*
cpe:2.3:a:sun:java_system_access_manager:7.1:*:solaris_10_sparc:*:*:*:*:*
cpe:2.3:a:sun:java_system_access_manager:7.1:*:solaris_10_windows:*:*:*:*:*
cpe:2.3:a:sun:java_system_access_manager:7.1:*:solaris_10_x86:*:*:*:*:*
cpe:2.3:a:sun:java_system_access_manager:7.1:*:solaris_8_linux:*:*:*:*:*
cpe:2.3:a:sun:java_system_access_manager:7.1:*:solaris_8_sparc:*:*:*:*:*
cpe:2.3:a:sun:java_system_access_manager:7.1:*:solaris_8_windows:*:*:*:*:*
cpe:2.3:a:sun:java_system_access_manager:7.1:*:solaris_8_x86:*:*:*:*:*
cpe:2.3:a:sun:java_system_access_manager:7.1:*:solaris_9_linux:*:*:*:*:*
cpe:2.3:a:sun:java_system_access_manager:7.1:*:solaris_9_sparc:*:*:*:*:*
cpe:2.3:a:sun:java_system_access_manager:7.1:*:solaris_9_windows:*:*:*:*:*
cpe:2.3:a:sun:java_system_access_manager:7.1:*:solaris_9_x86:*:*:*:*:*
cpe:2.3:a:sun:java_system_access_manager:7_2005q4:*:solaris_10_linux:*:*:*:*:*
cpe:2.3:a:sun:java_system_access_manager:7_2005q4:*:solaris_10_sparc:*:*:*:*:*
cpe:2.3:a:sun:java_system_access_manager:7_2005q4:*:solaris_10_windows:*:*:*:*:*
cpe:2.3:a:sun:java_system_access_manager:7_2005q4:*:solaris_10_x86:*:*:*:*:*
cpe:2.3:a:sun:java_system_access_manager:7_2005q4:*:solaris_8_linux:*:*:*:*:*
cpe:2.3:a:sun:java_system_access_manager:7_2005q4:*:solaris_8_sparc:*:*:*:*:*
cpe:2.3:a:sun:java_system_access_manager:7_2005q4:*:solaris_8_windows:*:*:*:*:*
cpe:2.3:a:sun:java_system_access_manager:7_2005q4:*:solaris_8_x86:*:*:*:*:*
cpe:2.3:a:sun:java_system_access_manager:7_2005q4:*:solaris_9_linux:*:*:*:*:*
cpe:2.3:a:sun:java_system_access_manager:7_2005q4:*:solaris_9_sparc:*:*:*:*:*
cpe:2.3:a:sun:java_system_access_manager:7_2005q4:*:solaris_9_windows:*:*:*:*:*
cpe:2.3:a:sun:java_system_access_manager:7_2005q4:*:solaris_9_x86:*:*:*:*:*
ID | Name | Product | Family | Severity |
---|---|---|---|---|
107950 | Solaris 10 (x86) : 126357-06 | Nessus | Solaris Local Security Checks | critical |
107871 | Solaris 10 (x86) : 120955-12 | Nessus | Solaris Local Security Checks | critical |
107821 | Solaris 10 (x86) : 119465-17 | Nessus | Solaris Local Security Checks | medium |
107450 | Solaris 10 (sparc) : 126356-06 | Nessus | Solaris Local Security Checks | critical |
107369 | Solaris 10 (sparc) : 120954-12 | Nessus | Solaris Local Security Checks | critical |
107318 | Solaris 10 (sparc) : 119465-17 | Nessus | Solaris Local Security Checks | medium |
5132 | Sun Java System Access Manager 7.1 < Patch 2 Multiple Vulnerabilities | Nessus Network Monitor | Web Servers | medium |
38126 | Solaris 10 (x86) : 120955-12 (deprecated) | Nessus | Solaris Local Security Checks | critical |
38005 | Solaris 9 (x86) : 120955-12 | Nessus | Solaris Local Security Checks | critical |
37533 | Solaris 9 (sparc) : 120954-12 | Nessus | Solaris Local Security Checks | critical |
37271 | Solaris 8 (sparc) : 120954-12 | Nessus | Solaris Local Security Checks | critical |
36756 | Solaris 10 (sparc) : 120954-12 (deprecated) | Nessus | Solaris Local Security Checks | critical |
35618 | Sun OpenSSO / Java System Access Manager Login Module User Account Enumeration Weakness | Nessus | CGI abuses | medium |
23611 | Solaris 9 (x86) : 119465-17 | Nessus | Solaris Local Security Checks | medium |
23553 | Solaris 9 (sparc) : 119465-17 | Nessus | Solaris Local Security Checks | medium |
23466 | Solaris 8 (x86) : 119465-17 | Nessus | Solaris Local Security Checks | medium |
23415 | Solaris 8 (sparc) : 119465-17 | Nessus | Solaris Local Security Checks | medium |
22989 | Solaris 10 (x86) : 119465-17 (deprecated) | Nessus | Solaris Local Security Checks | medium |
22956 | Solaris 10 (sparc) : 119465-17 (deprecated) | Nessus | Solaris Local Security Checks | medium |