TCMAN GIM
cpe:2.3:a:tcman:gim:*:*:*:*:*:*:*
- < 20250304
A user enumeration vulnerability exists in TCMAN GIM version 11.20250304, allowing unauthenticated attackers to verify the existence of users on the system. This is achieved by sending requests to the '/WS/PDAWebService.asmx' endpoint with specific parameters related to user identification.
Exploitation of this vulnerability allows for unauthorized user enumeration, potentially leading to further attacks such as password guessing or phishing.
Users can upgrade to TCMAN GIM version 20250401 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.