CVE Vulnerabilities

CVE-2020-26526

Published: Oct 02, 2020 | Modified: Oct 06, 2020
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in Damstra Smart Asset 2020.7. It is possible to enumerate valid usernames on the login page. The application sends a different server response when the username is invalid than when the username is valid (Unable to find an APIDomain versus Wrong email or password).

Affected Software

Name Vendor Start Version End Version
Smart_asset Damstratechnology 2020.7 (including) 2020.7 (including)

References