Username Enumeration Vulnerability in Hyland Onbase Application Server
CVE-2022-23342
Key Information:
Badges
What is CVE-2022-23342?
The Onbase Application Server is susceptible to a username enumeration vulnerability that allows an attacker to discern valid usernames from invalid ones through analyzing the different responses generated by the server. By conducting a POST request to the /mobilebroker/ServiceToBroker.svc/Json/Connect endpoint, an attacker can exploit this discrepancy, thereby gaining unauthorized insights into valid user accounts. This vulnerability can potentially compromise the integrity of Active Directory integrated systems, posing a significant risk to the security of user data.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
Vulnerability published
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability Reserved