CVE

Id
70400  
CVE No.
CVE-2014-3105  
Status
Candidate  
Description
The OSLC integration feature in the Web component in IBM Rational ClearQuest 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 provides different error messages for failed login attempts depending on whether the username exists, which allows remote attackers to enumerate account names via a series of requests.  
Phase
Assigned (20140429)  
Votes
None (candidate not yet proposed)  
Comments