351 – Automatic information enumeration - Corporate information
Description
It is possible to automatically enumerate system information such as finding IDs due to different messages for existing and non existing finding IDs.
Impact
Get all existing findings in the system.
Recommendation
Show the same response for existing and non-existing findings.
Threat
External attacker with access to integrates.
Expected Remediation Time
Score 4.0
Default score using CVSS 4.0. It may change depending on the context of the src.
Base 4.0
- Attack vector: N
- Attack complexity: L
- Attack Requirements: N
- Privileges required: L
- User interaction: N
- Confidentiality (VC): L
- Integrity (VI): N
- Availability (VA): N
- Confidentiality (SC): N
- Integrity (SI): N
- Availability (SA): N
Threat 4.0
- Exploit maturity: X