CVE-2022-23342
The Hyland Onbase Application Server releases prior to 20.3.58.1000 and OnBase releases 21.1.1.1000 through 21.1.15.1000 are vulnerable to a username enumeration vulnerability. An attacker can obtain valid users based on the response returned for invalid and valid users by sending a POST login request to the /mobilebroker/ServiceToBroker.svc/Json/Connect endpoint. This can lead to user enumeration against the underlying Active Directory integrated systems.
- Affected products
- Active Directory, Hyland Onbase, Hyland Onbase Application Server
- Hyland Onbase
- < 20.3.58.1000, 21.1.15.1000
- Fix
- Available
- CVSS 3.1
- 5.3 MEDIUM
- EPSS
- 1.3% (67th percentile)
- NVD status
- Modified
- Published
- 2022-06-21
CVE-2022-23342 at NVD
1 known exploit for CVE-2022-23342
Proof-of-concept code and exploit modules indexed by Sploitus