Username Enumeration Vulnerability in Hyland Onbase Application Server
CVE-2022-23342

5.3MEDIUM

Key Information:

Vendor

Hyland

Status
Vendor
CVE Published:
21 June 2022

Badges

👾 Exploit Exists🟡 Public PoC

What is CVE-2022-23342?

The Onbase Application Server is susceptible to a username enumeration vulnerability that allows an attacker to discern valid usernames from invalid ones through analyzing the different responses generated by the server. By conducting a POST request to the /mobilebroker/ServiceToBroker.svc/Json/Connect endpoint, an attacker can exploit this discrepancy, thereby gaining unauthorized insights into valid user accounts. This vulnerability can potentially compromise the integrity of Active Directory integrated systems, posing a significant risk to the security of user data.

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability Reserved

.