TCMAN GIM User Enumeration Vulnerability

Vulnerability

A user enumeration vulnerability exists in TCMAN GIM version 11, prior to 20250304. This vulnerability allows an unauthenticated attacker to verify the existence of a user account by exploiting the 'pda:username' parameter with the 'soapaction GetUserQuestionAndAnswer' in the '/WS/PDAWebService.asmx' endpoint.

Impact

Exploitation of this vulnerability allows for user enumeration, enabling an attacker to determine valid usernames on the system.

Remediation

Users can upgrade to TCMAN GIM version 20250401 to address this vulnerability.

Added: Dec 2, 2025, 2:21 PM
Updated: Dec 2, 2025, 5:44 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
4.7
remediation
7.7
relevance
1.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.