← Back
CVE-2026-27462
high
CVSS 7.5
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different responses for valid/invalid usernames depending on multiple factors in the reset password mechanism, lead...
Summary
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different responses for valid/invalid usernames depending on multiple factors in the reset password mechanism, leading to user enumeration. This issue has been fixed in version 3.2.3.
AI summary openai / gpt-4o
Combodo iTopのバージョン3.2.3より前では、パスワードリセット時に有効なユーザー名と無効なユーザー名に対して異なる応答を返すことで、ユーザーの列挙が可能となる脆弱性が存在します。この問題はバージョン3.2.3で修正されています。
❓ What is the problem
Combodo iTopにおけるパスワードリセットのメカニズムが、ユーザー名の有効性に基づいて異なる応答を返す脆弱性。
📍 Affected scope
iTopのバージョン3.2.3より前
🔥 Severity
高い重大度で、ユーザー列挙攻撃のリスクがある。
🔧 How to fix
iTopをバージョン3.2.3にアップデートすることで脆弱性が修正される。
🛡️ Workaround
情報なし
🔍 Detection
iTopのバージョンをチェックし、3.2.3未満であれば影響を受ける可能性がある。
References
- web [email protected]
- web [email protected]