CVE-2017-16629 describes an information disclosure vulnerability in SapphireIMS 4097_1 where an attacker can enumerate valid usernames by observing distinct error messages on the login form. This vulnerability has a CVSS score of 7.5 (High), indicating a significant risk due to its network-based attack vector, low attack complexity, and high confidentiality impact, allowing unauthorized access to user information. While there is no evidence of active exploitation, nor publicly available exploit code, the vulnerability's nature makes it a potential target for reconnaissance. The low EPSS score and lack of community discussion suggest it is not widely prioritized, but it remains a critical weakness for affected systems.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4097_1CPE matchmatch criteria | cpe:2.3:a:sapphireims:sapphireims:4097_1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.