Microsiga Protheus Username Enumeration Weakness
by Carol~
- 3/17/11 3:49 PM
In Reply to: VULNERABILITIES / FIXES - March 17, 2011 by Carol~
Release Date : 2011-03-17
Criticality level : Not critical
Impact : Exposure of sensitive information
Where : From local network
Solution Status: Unpatched
Software: Microsiga Protheus 10.x
Microsiga Protheus 8.x
Description:
Flavio do Carmo Junior has reported a weakness in Microsiga Protheus, which can be exploited by malicious people to disclose sensitive information.
The authentication procedure returns different messages depending on the existence of the provided username. This can be exploited to enumerate valid usernames.
The weakness is reported in versions 8 and 10. Other versions may also be affected.
Solution:
Restrict access to trusted users only.
Provided and/or discovered by:
Flavio do Carmo Junior (waKKu), DcLabs Security Research Group
Original Advisory:
http://archives.neohapsis.com/archives/bugtraq/2011-03/0062.html
http://secunia.com/advisories/43654/

Moderator
CNET Staff
Samsung Staff
Dell Staff