A vulnerability in Beta80 Life 1st enables the retrieval of different error messages for failed authentication attempts
(in case of the usage of a wrong password or a non existent user). The difference in the
returned error messages could be used by attackers to understand whether a
certain user is registered in the Identity Manager.
This issue affects Life 1st: 1.5.2.14234.
Metrics
Affected Vendors & Products
References
History
Wed, 02 Jul 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Exposure of Sensitive Information to an Unauthorized Actor vulnerability impacting Beta80 Life 1st Identity Manager allows User Enumeration using Authentication Rest APIs. Affected: Life 1st version 1.5.2.14234. Different error messages are returned to failed authentication attempts in case of the usage of a wrong password or a non existent user. This issue affects Life 1st: 1.5.2.14234. | A vulnerability in Beta80 Life 1st enables the retrieval of different error messages for failed authentication attempts (in case of the usage of a wrong password or a non existent user). The difference in the returned error messages could be used by attackers to understand whether a certain user is registered in the Identity Manager. This issue affects Life 1st: 1.5.2.14234. |
| References |
|
Wed, 19 Mar 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 19 Mar 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Exposure of Sensitive Information to an Unauthorized Actor vulnerability impacting Beta80 Life 1st Identity Manager allows User Enumeration using Authentication Rest APIs. Affected: Life 1st version 1.5.2.14234. Different error messages are returned to failed authentication attempts in case of the usage of a wrong password or a non existent user. This issue affects Life 1st: 1.5.2.14234. | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ENISA
Published: 2025-03-19T15:27:55.960Z
Updated: 2025-07-02T14:20:20.635Z
Reserved: 2025-02-11T08:24:51.660Z
Link: CVE-2025-26485
Updated: 2025-03-19T17:33:39.933Z
Status : Awaiting Analysis
Published: 2025-03-19T16:15:31.257
Modified: 2025-07-02T15:15:25.687
Link: CVE-2025-26485
No data.