User enumeration can occur in the Authentication REST API in Delinea PAM Secret Server 11.4. This allows a remote attacker to determine whether a user is valid because of a difference in responses from the /oauth2/token endpoint.
oryginał ENCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NDelinea Secret Server
APPDelinea11.4.000000
Powiązane podatności
Delinea Secret Server — brak weryfikacji integralności pakietów aktualizacji
Delinea Secret Server before 11.7.000001 allows attackers to bypass authentication via the SOAP API in SecretS...
In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or w...
Podatność w ramach improper authentication w Delinea Inc. Secret Server On-Prem (moduły RPC Password Rotation)...
Delinea addressed a reported case on Secret Server v11.7.31 (protocol handler version 6.0.3.26) where, within ...