CVE-2010-3979
SAP BusinessObjects Enterprise XI 3.2 - Unauthenticated Username Enumeration via Login SOAPAction Error Messages
Title source: llmDescription
Dswsbobje in SAP BusinessObjects Enterprise XI 3.2 generates different error messages depending on whether the Login field corresponds to a valid username, which allows remote attackers to enumerate account names via a login SOAPAction to the dswsbobje/services/session URI.
References (1)
Core 1
Core References
Exploit x_refsource_misc
http://spl0it.org/files/talks/source_barcelona10/Hacking%20SAP%20BusinessObjects.pdf
Scores
EPSS
0.0025
EPSS Percentile
48.3%
Details
CWE
CWE-200
Status
published
Products (1)
sap/businessobjects
3.2
Published
Oct 18, 2010
Tracked Since
Feb 18, 2026