Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-15132


Zabbix through 4.4.0alpha1 allows User Enumeration. With login requests, it is possible to enumerate application usernames based on the variability of server responses (e.g., the "Login name or password is incorrect" and "No permissions for system access" messages, or just blocking for a number of seconds). This affects both api_jsonrpc.php and index.php.


Published

2019-08-17T18:15:10.690

Last Modified

2024-11-21T04:28:07.297

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-203

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application zabbix zabbix ≤ 4.0.26 Yes
Application zabbix zabbix ≤ 5.0.5 Yes
Application zabbix zabbix ≤ 5.2.1 Yes
Application zabbix zabbix 4.4.0 Yes
Operating System debian debian_linux 9.0 Yes

References