IBM Rational ClearQuest 7.0.1.1 and 7.0.0.2 generates different error messages depending on whether the username is valid or invalid, which allows remote attackers to enumerate usernames.Referenceshttp://www.securitytracker.com/id?1019566https://exchange.xforce.ibmcloud.com/vulnerabilities/41042http://secunia.com/advisories/29280http://www-1.ibm.com/support/docview.wss?uid=swg1PK55561http://www.securityfocus.com/bid/28132http://www.vupen.com/english/advisories/2008/0804/references