vendor:
LogicalDOC
by:
Gjoko 'LiquidWorm' Krstic
5.5
CVSS
MEDIUM
Username Enumeration Weakness
200
CWE
Product Name: LogicalDOC
Affected Version From: 7.1.2001
Affected Version To: 7.7.2004
Patch Exists: NO
Related CWE:
CPE: LogicalDOC Srl
Platforms Tested: Windows 10, Linux Ubuntu 16.04, Java 1.8.0_161, Apache-Coyote/1.1, Apache Tomcat/8.5.24, Apache Tomcat/8.5.13, Undisclosed 8.41
2018
LogicalDOC Enterprise 7.7.4 Username Enumeration Weakness
The weakness is caused due to the 'j_spring_security_check' script and how it verifies provided credentials. An attacker can use this weakness to enumerate valid users on the affected node.
Mitigation:
Upgrade to a version of LogicalDOC that has patched this vulnerability.