A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.2). The login implementation of the affected application contains an observable response discrepancy vulnerability when validating usernames. This could allow an unauthenticated remote attacker to distinguish between valid and invalid usernames.
Metrics
Affected Vendors & Products
References
History
Fri, 22 Aug 2025 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Siemens
Siemens polarion Alm |
|
CPEs | cpe:2.3:a:siemens:polarion_alm:*:*:*:*:*:*:*:* cpe:2.3:a:siemens:polarion_alm:2310:*:*:*:*:*:*:* |
|
Vendors & Products |
Siemens
Siemens polarion Alm |
Tue, 13 May 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 13 May 2025 09:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.2). The login implementation of the affected application contains an observable response discrepancy vulnerability when validating usernames. This could allow an unauthenticated remote attacker to distinguish between valid and invalid usernames. | |
Weaknesses | CWE-204 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: siemens
Published: 2025-05-13T09:38:25.452Z
Updated: 2025-05-13T15:57:37.712Z
Reserved: 2024-10-28T07:01:23.767Z
Link: CVE-2024-51447

Updated: 2025-05-13T15:44:06.861Z

Status : Analyzed
Published: 2025-05-13T10:15:21.940
Modified: 2025-08-22T20:32:20.717
Link: CVE-2024-51447

No data.