5
CVSSv2

CVE-2022-23342

Published: 21/06/2022 Updated: 29/06/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The Hyland Onbase Application Server releases before 20.3.58.1000 and OnBase releases 21.1.1.1000 up to and including 21.1.15.1000 are vulnerable to a username enumeration vulnerability. An attacker can obtain valid users based on the response returned for invalid and valid users by sending a POST login request to the /mobilebroker/ServiceToBroker.svc/Json/Connect endpoint. This can lead to user enumeration against the underlying Active Directory integrated systems.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

hyland onbase

Github Repositories

CVE-2022-23342 Security Advisory – Username Enumeration in OnBase Affected software versions and builds: OnBase Application Server OnBase releases prior to 203581000 and OnBase releases 21111000 through 211151000 are impacted Fixed software versions and builds: OnBase EP3 releases greater than or equal to 203581000 OnBase EP5 releases greater than or equal to