User Enumeration Vulnerability in Saviynt Enterprise Identity Cloud
CVE-2022-23856
5.3MEDIUM
What is CVE-2022-23856?
A user enumeration vulnerability was identified in Saviynt's Enterprise Identity Cloud (EIC) version 5.5 SP2.x that enables attackers to manipulate the 'id' parameter in URLs such as 'ECM/maintenance/forgotpasswordstep1' to enumerate existing user accounts. This exploitation can lead to unauthorized access attempts and increase the risk of targeted attacks. Organizations should implement measures to mitigate this risk immediately.