Описание
HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Valid usernames, Email addresses used for login, Account identifiers If the system is accessed from shared environments, attackers may enumerate valid usernames through browser suggestions.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:hcltech:icontrol:4.4.0:*:*:*:*:*:*:*
EPSS
Процентиль: 7%
0.00177
Низкий
3.7 Low
CVSS3
5.3 Medium
CVSS3
Дефекты
CWE-522
Связанные уязвимости
CVSS3: 3.7
github
около 1 месяца назад
HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Valid usernames, Email addresses used for login, Account identifiers If the system is accessed from shared environments, attackers may enumerate valid usernames through browser suggestions.
EPSS
Процентиль: 7%
0.00177
Низкий
3.7 Low
CVSS3
5.3 Medium
CVSS3
Дефекты
CWE-522