Novell iChain 2.2 before Support Pack 1 uses a shorter timeout for a non-existent user than a valid user, which makes it easier for remote attackers to guess usernames and conduct brute force password guessing.
Score: 3.25
Priority: P2 - Serious (High)
Score: 0.00946Percentile: 0.75341
CVSS v2 Score: 5.0
Severity:
← Back to Home