Executive brief
A vulnerability exists in the login interface of Canias ERP, a business management software suite. An attacker can observe differences in how the system responds to login attempts to determine valid usernames or other sensitive system states. While difficult to execute, this could allow an unauthorized party to gather information necessary for a more targeted attack against corporate accounts.
Technical details
An observable response discrepancy vulnerability (CWE-204/CWE-203) exists in the doAction function of the Login RMI Interface in IAS Canias ERP 8.03. By manipulating login requests, a remote attacker can distinguish between different error states (such as 'User Not Found' vs 'Wrong Password') based on the server's response. This information disclosure facilitates username enumeration. The attack requires a high degree of complexity and is considered difficult to exploit. A public exploit or proof-of-concept exists, and the vendor has reportedly not responded to the disclosure.
Affected products
- Industrial Application Software (IAS) Canias ERP 8.03
Timeline
- 2026-04-20: other: Initial public gist/exploit published
- 2026-05-10: advisory: CVE published and added to NVD