Forum Discussion

0_168831's avatar
0_168831
Icon for Nimbostratus rankNimbostratus
May 12, 2015

Someone claiming "User Enumeration Flaw" in BIG-IQ, pretty sure its intended behavior

Recently came across this post it's kind of hard to understand, but I'm almost sure that this is the intended behavior of the REST API considering you have to log in to access the URL. I think it's kind of silly to expose the user's password hash but this really shouldn't be an issue if the hash algorithm is strong enough, not to mention the fact that only legitimate users can access this part of the API. I was wondering if I can get some confirmation, or see what you guys think about this.

 

4 Replies