User Enumeration Vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attacker to determine whether a user exists on the system. The vulnerability is exploitable through the 'pda:username' parameter with 'soapaction GetLastDatePasswordChange' in '/WS/PDAWebService.asmx'.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
The vulnerabilitiy has been fixed by the TCMAN team in version 20250401.
Workaround
No workaround given by the vendor.
References
History
Tue, 02 Dec 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | User Enumeration Vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attacker to determine whether a user exists on the system. The vulnerability is exploitable through the 'pda:username' parameter with 'soapaction GetLastDatePasswordChange' in '/WS/PDAWebService.asmx'. | |
| Title | User Enumeration vulnerability in TCMAN GIM | |
| First Time appeared |
Tcman
Tcman gim |
|
| Weaknesses | CWE-200 | |
| CPEs | cpe:2.3:a:tcman:gim:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Tcman
Tcman gim |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-12-02T14:23:16.382Z
Reserved: 2025-04-16T09:08:43.218Z
Link: CVE-2025-41014
No data.
Status : Received
Published: 2025-12-02T14:16:24.597
Modified: 2025-12-02T14:16:24.597
Link: CVE-2025-41014
No data.
OpenCVE Enrichment
No data.