CVE-2021-29842
16.09.2021, 16:15
IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0 and Liberty 17.0.0.3 through 21.0.0.9 could allow a remote user to enumerate usernames due to a difference of responses from valid and invalid login attempts. IBM X-Force ID: 205202.Enginsight
Vendor | Product | Version |
---|---|---|
ibm | websphere_application_server | 7.0.0.0 ≤ 𝑥 ≤ 7.0.0.45 |
ibm | websphere_application_server | 8.0.0.0 ≤ 𝑥 ≤ 8.0.0.15 |
ibm | websphere_application_server | 8.5 ≤ 𝑥 ≤ 8.5.5.20 |
ibm | websphere_application_server | 9.0.0.0 ≤ 𝑥 ≤ 9.0.5.9 |
ibm | websphere_application_server | 17.0.0.3 ≤ 𝑥 ≤ 21.0.0.9 |
𝑥
= Vulnerable software versions