TCMAN GIM User Enumeration Vulnerability

Vulnerability

A user enumeration vulnerability exists in TCMAN GIM version 11.20250304, allowing unauthenticated attackers to verify the existence of users on the system. This is achieved by sending requests to the '/WS/PDAWebService.asmx' endpoint with specific parameters related to user identification.

Impact

Exploitation of this vulnerability allows for unauthorized user enumeration, potentially leading to further attacks such as password guessing or phishing.

Remediation

Users can upgrade to TCMAN GIM version 20250401 to address this vulnerability.

Added: Dec 2, 2025, 1:16 PM
Updated: Dec 2, 2025, 5:47 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
4.7
remediation
7.7
relevance
1.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.