Ipswitch MOVEit DMZ prior to 8.2 provides different error messages for authentication attempts depending on whether the user account exists, which allows remote malicious users to enumerate usernames via a series of SOAP requests to machine.aspx.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
ipswitch moveit dmz |