BMC Remedy Action Request System 5.01.02 Patch 1267 generates different error messages for failed login attempts with a valid username than for those with an invalid username, which allows remote attackers to determine valid account names.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Remedy_action_request_system | Bmc | 5.01.02_patch_1267 (including) | 5.01.02_patch_1267 (including) |