CVE-2022-23342
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Hyland Onbase Application Server releases prior to 20.3.58.1000 and OnBase releases 21.1.1.1000 through 21.1.15.1000 are vulnerable to a username enumeration vulnerability. An attacker can obtain valid users based on the response returned for invalid and valid users by sending a POST login request to the /mobilebroker/ServiceToBroker.svc/Json/Connect endpoint. This can lead to user enumeration against the underlying Active Directory integrated systems.
Hyland Onbase Application Server versiones anteriores a 20.3.58.1000 y OnBase versiones 21.1.1.1000 hasta 21.1.15.1000, son susceptibles a una vulnerabilidad de enumeración de nombres de usuario. Un atacante puede obtener usuarios válidos basándose en la respuesta devuelta para usuarios no válidos y válidos mediante el envío de una petición POST de inicio de sesión al endpoint /mobilebroker/ServiceToBroker.svc/Json/Connect. Esto puede conllevar a una enumeración de usuarios contra los sistemas integrados de Active Directory subyacentes
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-01-18 CVE Reserved
- 2022-06-21 CVE Published
- 2024-01-12 EPSS Updated
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/InitRoot/CVE-2022-23342 | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Hyland Search vendor "Hyland" | Onbase Search vendor "Hyland" for product "Onbase" | < 20.3.58.1000 Search vendor "Hyland" for product "Onbase" and version " < 20.3.58.1000" | - |
Affected
| ||||||
Hyland Search vendor "Hyland" | Onbase Search vendor "Hyland" for product "Onbase" | >= 21.1.1.1000 <= 21.1.15.1000 Search vendor "Hyland" for product "Onbase" and version " >= 21.1.1.1000 <= 21.1.15.1000" | - |
Affected
|