A vulnerability in Beta80 Life 1st enables the retrieval of different error messages for failed authentication attempts
(in case of the usage of a wrong password or a non existent user). The difference in the
returned error messages could be used by attackers to understand whether a
certain user is registered in the Identity Manager.
This issue affects Life 1st: 1.5.2.14234.
Metrics
Affected Vendors & Products
References
History
Wed, 02 Jul 2025 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Exposure of Sensitive Information to an Unauthorized Actor vulnerability impacting Beta80 Life 1st Identity Manager allows User Enumeration using Authentication Rest APIs. Affected: Life 1st version 1.5.2.14234. Different error messages are returned to failed authentication attempts in case of the usage of a wrong password or a non existent user. This issue affects Life 1st: 1.5.2.14234. | A vulnerability in Beta80 Life 1st enables the retrieval of different error messages for failed authentication attempts (in case of the usage of a wrong password or a non existent user). The difference in the returned error messages could be used by attackers to understand whether a certain user is registered in the Identity Manager. This issue affects Life 1st: 1.5.2.14234. |
References |
|
Wed, 19 Mar 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 19 Mar 2025 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Exposure of Sensitive Information to an Unauthorized Actor vulnerability impacting Beta80 Life 1st Identity Manager allows User Enumeration using Authentication Rest APIs. Affected: Life 1st version 1.5.2.14234. Different error messages are returned to failed authentication attempts in case of the usage of a wrong password or a non existent user. This issue affects Life 1st: 1.5.2.14234. | |
Weaknesses | CWE-200 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: ENISA
Published: 2025-03-19T15:27:55.960Z
Updated: 2025-07-02T14:20:20.635Z
Reserved: 2025-02-11T08:24:51.660Z
Link: CVE-2025-26485

Updated: 2025-03-19T17:33:39.933Z

Status : Awaiting Analysis
Published: 2025-03-19T16:15:31.257
Modified: 2025-07-02T15:15:25.687
Link: CVE-2025-26485

No data.