5
CVSSv2

CVE-2021-44875

Published: 21/12/2021 Updated: 27/12/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to User enumeration. The Systeam application is an ERP system that uses a mixed architecture based on SaaS tenant and user management, and on-premise database and web application counterparts. This issue occurs during the password recovery procedure for a given user, where a difference in messages could allow an malicious user to determine if the given user is valid or not, enabling a brute force attack with valid users.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dalmark systeam enterprise resource planning 2.22.8