Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-41014


User Enumeration Vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attacker to determine whether a user exists on the system. The vulnerability is exploitable through the 'pda:username' parameter with 'soapaction GetLastDatePasswordChange' in '/WS/PDAWebService.asmx'.


Published

2025-12-02T14:16:24.597

Last Modified

2025-12-03T20:07:15.970

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application tcman gim < 2025-04-01 Yes

References