cbcvebase.
CVE-2021-29842
published 2021-09-16

CVE-2021-29842: IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0 and Liberty 17.0.0.3 through 21.0.0.9 could allow a remote user to enumerate usernames due to a difference…

medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0 and Liberty 17.0.0.3 through 21.0.0.9 could allow a remote user to enumerate usernames due to a difference of responses from valid and invalid login attempts. IBM X-Force ID: 205202.

Affected

11 ranges
VendorProductVersion rangeFixed in
ibmwebsphere_application_server
ibmwebsphere_application_server
ibmwebsphere_application_server
ibmwebsphere_application_server
ibmwebsphere_application_server17.0.0.3 – 21.0.0.9
ibmwebsphere_application_server7.0.0.0 – 7.0.0.45
ibmwebsphere_application_server8.0.0.0 – 8.0.0.15
ibmwebsphere_application_server8.5 – 8.5.5.20
ibmwebsphere_application_server9.0.0.0 – 9.0.5.9
ibmwebsphere_application_server_liberty
ibmwebsphere_application_server_liberty