vendor:
AS/400
by:
SecurityFocus
3.3
CVSS
MEDIUM
Information Disclosure
200
CWE
Product Name: AS/400
Affected Version From: OS/400
Affected Version To: OS/400
Patch Exists: N/A
Related CWE: N/A
CPE: o:ibm:as400
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2002
Information Disclosure Vulnerability in OS/400 Systems
An information disclosure vulnerability has been reported to exist in OS/400 systems. An authenticated user may be able to obtain a list of all valid user accounts. The user must be running a 5250 emulator. The user may, after authentication, access the 'System Request' menu and obtain a list of all object names of type USRPRF. The 'System Request' feature is installed by default.
Mitigation:
Restrict access to the 'System Request' feature and ensure that only authorized personnel are able to access it.