Siemens Polarion V2310
cpe:2.3:a:siemens:polarion:*:*:*:*:*:*:*
- >= V2404, < V2404.2
A vulnerability exists in Siemens Polarion versions prior to 2410 and in all versions of Polarion V2404 prior to V2404.2. The issue arises from the login implementation, which exhibits an observable response discrepancy when validating usernames. This vulnerability could enable an unauthenticated remote attacker to differentiate between valid and invalid usernames.
Exploitation of this vulnerability allows for username enumeration, where an attacker can identify valid usernames within the application.
Users are advised to update Polarion to version 2410 or later. For Polarion V2404, patch releases are available.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.