The HCL Domino AppDev Pack IAM service is susceptible to...
Moderate severity
Unreviewed
Published
Jul 6, 2023
to the GitHub Advisory Database
•
Updated Jan 17, 2025
Description
Published by the National Vulnerability Database
May 23, 2023
Published to the GitHub Advisory Database
Jul 6, 2023
Last updated
Jan 17, 2025
The HCL Domino AppDev Pack IAM service is susceptible to a User Account Enumeration vulnerability. During a failed login attempt a difference in messages could allow an attacker to determine if the user is valid or not. The attacker could use this information to focus a brute force attack on valid users.
References