5
CVSSv2

CVE-2019-15132

Published: 17/08/2019 Updated: 12/04/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Zabbix up to and including 4.4.0alpha1 allows User Enumeration. With login requests, it is possible to enumerate application usernames based on the variability of server responses (e.g., the "Login name or password is incorrect" and "No permissions for system access" messages, or just blocking for a number of seconds). This affects both api_jsonrpc.php and index.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zabbix zabbix 4.4.0

zabbix zabbix

debian debian linux 9.0

Vendor Advisories

Debian Bug report logs - #935027 zabbix: CVE-2019-15132 Package: src:zabbix; Maintainer for src:zabbix is Dmitry Smirnov <onlyjob@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 18 Aug 2019 08:51:01 UTC Severity: important Tags: security, upstream Found in version zabbix/1:404+dfsg-1 ...