CVE-2010-3979

SAP BusinessObjects Enterprise XI 3.2 - Unauthenticated Username Enumeration via Login SOAPAction Error Messages

Title source: llm
STIX 2.1

Description

Dswsbobje in SAP BusinessObjects Enterprise XI 3.2 generates different error messages depending on whether the Login field corresponds to a valid username, which allows remote attackers to enumerate account names via a login SOAPAction to the dswsbobje/services/session URI.

References (1)

Core 1

Scores

EPSS 0.0025
EPSS Percentile 48.3%

Details

CWE
CWE-200
Status published
Products (1)
sap/businessobjects 3.2
Published Oct 18, 2010
Tracked Since Feb 18, 2026