Vulnerabilities > CVE-2009-2435 - Credentials Management vulnerability in IBM Lotus Instant Messaging and web Conferencing 6.5.1
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
The Sametime server in IBM Lotus Instant Messaging and Web Conferencing 6.5.1 generates error messages for a failed logon attempt with different time delays depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |