In Knowage up to and including 6.1.1, an unauthenticated user can enumerated valid usernames via the ChangePwdServlet page.
knowage-suite knowage