CVE-2019-15132
Last modified
CVE-2019-15132 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Zabbix through 4.4.0alpha1 allows User Enumeration. With login requests, it is possible to enumerate application usernames based on the variability of server responses (e.g., the "Login name or password is incorrect" and "No permissions for system access" messages, or just blocking for a number of seconds). EPSS estimates a 2.03% chance of exploitation in the next 30 days.
Description
Zabbix through 4.4.0alpha1 allows User Enumeration. With login requests, it is possible to enumerate application usernames based on the variability of server responses (e.g., the "Login name or password is incorrect" and "No permissions for system access" messages, or just blocking for a number of seconds). This affects both api_jsonrpc.php and index.php.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Zabbix | Zabbix | <= 4.0.26 | — |
| Zabbix | Zabbix | >= 5.0.0, <= 5.0.5 | — |
| Zabbix | Zabbix | >= 5.2.0, <= 5.2.1 | — |
| Zabbix | Zabbix | 4.4.0 | Alpha1 |
| Debian | Debian Linux | 9.0 | — |
References
- https://lists.debian.org/debian-lts-announce/2021/04/msg00018.htmlMailing List, Third Party Advisory
- https://support.zabbix.com/browse/ZBX-16532Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2021/04/msg00018.htmlMailing List, Third Party Advisory
- https://support.zabbix.com/browse/ZBX-16532Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-15132?
How severe is CVE-2019-15132?
How do I fix CVE-2019-15132?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-15127REDCap before 9.3.0 allows XSS attacks against non-administr…
- CVE-2019-15128iF.SVNAdmin through 1.6.2 allows svnadmin/usercreate.php CSR…
- CVE-2019-15129The Recruitment module in Humanica Humatrix 7 1.0.0.203 and …
- CVE-2019-1513Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-15130The Recruitment module in Humanica Humatrix 7 1.0.0.203 and …
- CVE-2019-15131In Code42 Enterprise 6.7.5 and earlier, 6.8.4 through 6.8.8,…9.8
- CVE-2019-15133In GIFLIB before 2019-02-16, a malformed GIF file triggers a…6.5
- CVE-2019-15134RIOT through 2019.07 contains a memory leak in the TCP imple…
- CVE-2019-15135The handshake protocol in Object Management Group (OMG) DDS …
- CVE-2019-15136The Access Control plugin in eProsima Fast RTPS through 1.9.…
- CVE-2019-15137The Access Control plugin in eProsima Fast RTPS through 1.9.…
- CVE-2019-15138The html-pdf package 2.2.0 for Node.js has an arbitrary file…7.5
Are you affected by CVE-2019-15132?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
