Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in One Identity Password Manager 5.8. An attacker could enumerate valid answers for a user. It is possible for an attacker to detect a valid answer based on the HTTP response content, and reuse this answer later for a password reset on a chosen password. The enumeration is possible because, within the HTTP response content, WRONG ID is only returned when the answer is incorrect.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
One Identity Password Manager 信息泄露漏洞
Vulnerability Description
One Identity Password Manager是美国One Identity公司的一个用于提供身份验证的Web平台。 One Identity Password Manager 5.8版本存在安全漏洞,攻击者可利用该漏洞可能会根据HTTP响应内容检测到一个有效的答案,并在以后重用这个答案以根据所选的密码重置密码。枚举是可能的,因为在HTTP响应内容中,只有当答案不正确时才返回错误的ID。
CVSS Information
N/A
Vulnerability Type
N/A