Lucene search

K
ubuntucveUbuntu.comUB:CVE-2012-5055
HistoryDec 05, 2012 - 12:00 a.m.

CVE-2012-5055

2012-12-0500:00:00
ubuntu.com
ubuntu.com
16

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.003

Percentile

68.3%

DaoAuthenticationProvider in VMware SpringSource Spring Security before
2.0.8, 3.0.x before 3.0.8, and 3.1.x before 3.1.3 does not check the
password if the user is not found, which makes the response delay shorter
and might allow remote attackers to enumerate valid usernames via a series
of login requests.

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.003

Percentile

68.3%