Likely 0-day
Perforce server contained user accounts with no password set, allowing unauthenticated access as those users. The user-users RPC was issued with the tag parameter to switch the server to tagged (client-FstatInfo) output, which omits the Password field entirely for passwordless accounts. Both ASCII and Unicode server modes were affected. SSL-enforcing servers are not affected.
id: perforce-passwordless-users
info:
name: Perforce Server - Passwordless User Accounts
author
...