No analysis available yet.
Vendor Solution
The vulnerabilitiy has been fixed by the TCMAN team in version 20250401.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 03 Dec 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 02 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 02 Dec 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | User Enumeration Vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attacker to determine whether a user exists on the system. The vulnerability is exploitable through the 'pda:username' parameter with 'soapaction GetUserQuestionAndAnswer' in '/WS/PDAWebService.asmx'. | |
| Title | User Enumeration vulnerability in TCMAN GIM | |
| First Time appeared |
Tcman
Tcman gim |
|
| Weaknesses | CWE-200 | |
| CPEs | cpe:2.3:a:tcman:gim:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Tcman
Tcman gim |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-12-02T14:23:47.055Z
Reserved: 2025-04-16T09:09:25.289Z
Link: CVE-2025-41015
Updated: 2025-12-02T14:23:43.322Z
Status : Analyzed
Published: 2025-12-02T14:16:24.753
Modified: 2025-12-03T20:08:14.570
Link: CVE-2025-41015
No data.
OpenCVE Enrichment
No data.