Loading
Ipswitch MOVEit DMZ before 8.2 provides different error messages for authentication attempts depending on whether the user account exists, which allows remote attackers to enumerate usernames via a series of SOAP requests to machine.aspx.
Use CWE-200, Ipswitch vendor hub and Moveit Dmz product page to widen CVE-2015-7680 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2017-6195, CVE-2015-7675 and CVE-2015-7676 for nearby disclosures in the same product family.