VYPR
High severity7.5NVD Advisory· Published Dec 2, 2025· Updated Sep 25, 2026

CVE-2025-41014

CVE-2025-41014

Description

User Enumeration Vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attacker to determine whether a user exists on the system. The vulnerability is exploitable through the 'pda:username' parameter with 'soapaction GetLastDatePasswordChange' in '/WS/PDAWebService.asmx'.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • TCMAN/GIM3 versions
    cpe:2.3:a:tcman:gim:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:tcman:gim:*:*:*:*:*:*:*:*range: <2025-04-01
    • (no CPE)range: 0
    • (no CPE)range: 20250304

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.