CVE-2022-23856
24.01.2022, 02:15
An issue was discovered in Saviynt Enterprise Identity Cloud (EIC) 5.5 SP2.x. An attacker can enumerate users by changing the id parameter, such as for the ECM/maintenance/forgotpasswordstep1 URI.Enginsight
Vendor | Product | Version |
---|---|---|
saviynt | enterprise_identity_cloud | - |
𝑥
= Vulnerable software versions
Common Weakness Enumeration