Логотип exploitDog
bind:CVE-2012-5055
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2012-5055

Количество 4

Количество 4

ubuntu логотип

CVE-2012-5055

около 13 лет назад

DaoAuthenticationProvider in VMware SpringSource Spring Security before 2.0.8, 3.0.x before 3.0.8, and 3.1.x before 3.1.3 does not check the password if the user is not found, which makes the response delay shorter and might allow remote attackers to enumerate valid usernames via a series of login requests.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2012-5055

больше 13 лет назад

DaoAuthenticationProvider in VMware SpringSource Spring Security before 2.0.8, 3.0.x before 3.0.8, and 3.1.x before 3.1.3 does not check the password if the user is not found, which makes the response delay shorter and might allow remote attackers to enumerate valid usernames via a series of login requests.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2012-5055

около 13 лет назад

DaoAuthenticationProvider in VMware SpringSource Spring Security before 2.0.8, 3.0.x before 3.0.8, and 3.1.x before 3.1.3 does not check the password if the user is not found, which makes the response delay shorter and might allow remote attackers to enumerate valid usernames via a series of login requests.

CVSS2: 5
EPSS: Низкий
github логотип

GHSA-3533-rvpc-6x56

больше 3 лет назад

Exposure of Sensitive Information to an Unauthorized Actor in Spring Security

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2012-5055

DaoAuthenticationProvider in VMware SpringSource Spring Security before 2.0.8, 3.0.x before 3.0.8, and 3.1.x before 3.1.3 does not check the password if the user is not found, which makes the response delay shorter and might allow remote attackers to enumerate valid usernames via a series of login requests.

CVSS2: 5
0%
Низкий
около 13 лет назад
redhat логотип
CVE-2012-5055

DaoAuthenticationProvider in VMware SpringSource Spring Security before 2.0.8, 3.0.x before 3.0.8, and 3.1.x before 3.1.3 does not check the password if the user is not found, which makes the response delay shorter and might allow remote attackers to enumerate valid usernames via a series of login requests.

CVSS2: 2.6
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2012-5055

DaoAuthenticationProvider in VMware SpringSource Spring Security before 2.0.8, 3.0.x before 3.0.8, and 3.1.x before 3.1.3 does not check the password if the user is not found, which makes the response delay shorter and might allow remote attackers to enumerate valid usernames via a series of login requests.

CVSS2: 5
0%
Низкий
около 13 лет назад
github логотип
GHSA-3533-rvpc-6x56

Exposure of Sensitive Information to an Unauthorized Actor in Spring Security

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу