Microsiga Protheus Username Enumeration Weakness

by Carol~ Moderator - 3/17/11 3:49 PM

In Reply to: VULNERABILITIES / FIXES - March 17, 2011 by Carol~ Moderator

Release Date : 2011-03-17

Criticality level : Not critical
Impact : Exposure of sensitive information
Where : From local network
Solution Status: Unpatched

Software: Microsiga Protheus 10.x
Microsiga Protheus 8.x

Description:
Flavio do Carmo Junior has reported a weakness in Microsiga Protheus, which can be exploited by malicious people to disclose sensitive information.

The authentication procedure returns different messages depending on the existence of the provided username. This can be exploited to enumerate valid usernames.

The weakness is reported in versions 8 and 10. Other versions may also be affected.

Solution:
Restrict access to trusted users only.

Provided and/or discovered by:
Flavio do Carmo Junior (waKKu), DcLabs Security Research Group

Original Advisory:
http://archives.neohapsis.com/archives/bugtraq/2011-03/0062.html

http://secunia.com/advisories/43654/