TCMAN GIM
cpe:2.3:a:tcman:gim:*:*:*:*:*:*:*
- < 20250304
A user enumeration vulnerability exists in TCMAN GIM version 11, prior to 20250304. This vulnerability allows an unauthenticated attacker to verify the existence of a user account by exploiting the 'pda:username' parameter with the 'soapaction GetLastDatePasswordChange' in the '/WS/PDAWebService.asmx' endpoint.
Exploitation of this vulnerability allows for user enumeration, enabling an attacker to determine valid usernames on the system.
Users can upgrade to TCMAN GIM version 20250401 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.