5
CVSSv2

CVE-2012-5055

Published: 05/12/2012 Updated: 28/12/2012
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

DaoAuthenticationProvider in VMware SpringSource Spring Security prior to 2.0.8, 3.0.x prior to 3.0.8, and 3.1.x prior to 3.1.3 does not check the password if the user is not found, which makes the response delay shorter and might allow remote malicious users to enumerate valid usernames via a series of login requests.

Vulnerable Product Search on Vulmon Subscribe to Product

vmware springsource spring security 2.0.1

vmware springsource spring security 2.0.2

vmware springsource spring security 2.0.3

vmware springsource spring security 2.0.4

vmware springsource spring security 2.0.0

vmware springsource spring security 2.0.5

vmware springsource spring security

vmware springsource spring security 3.0.1

vmware springsource spring security 3.0.2

vmware springsource spring security 3.0.3

vmware springsource spring security 3.0.4

vmware springsource spring security 3.0.0

vmware springsource spring security 3.0.5

vmware springsource spring security 3.1.2

vmware springsource spring security 3.1.1