Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, generates different responses for valid and invalid usernames, which allows remote attackers to identify valid users on the server.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published: 2002-08-31T04:00:00
Updated: 2024-08-08T03:12:16.625Z
Reserved: 2002-08-30T00:00:00
Link: CVE-2002-1064

No data.

Status : Deferred
Published: 2002-10-04T04:00:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2002-1064

No data.