CVE-2010-1221

CA XOsoft r12.0 and r12.5 does not properly perform authentication, which allows remote attackers to enumerate usernames via a SOAP request.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ca:xosoft_content_distribution:r12.0:*:*:*:*:*:*:*
cpe:2.3:a:ca:xosoft_content_distribution:r12.5:*:*:*:*:*:*:*
cpe:2.3:a:ca:xosoft_high_availability:r12.0:*:*:*:*:*:*:*
cpe:2.3:a:ca:xosoft_high_availability:r12.5:*:*:*:*:*:*:*
cpe:2.3:a:ca:xosoft_replication:r12.0:*:*:*:*:*:*:*
cpe:2.3:a:ca:xosoft_replication:r12.5:*:*:*:*:*:*:*

History

No history.

Information

Published : 2010-04-07 15:30

Updated : 2023-12-10 11:03


NVD link : CVE-2010-1221

Mitre link : CVE-2010-1221

CVE.ORG link : CVE-2010-1221


JSON object : View

Products Affected

ca

  • xosoft_high_availability
  • xosoft_content_distribution
  • xosoft_replication
CWE
CWE-287

Improper Authentication