CVE-2009-2435

CVE-2009-2435

CVE-2009-2435 · MEDIUM Severity

AV:N/AC:L/AU:N/C:P/I:N/A:N

The Sametime server in IBM Lotus Instant Messaging and Web Conferencing 6.5.1 generates error messages for a failed logon attempt with different time delays depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.

Learn more about our Cis Benchmark Audit For Ibm I.