logo

351 Automatic information enumeration - Corporate information


Description

It is possible to automatically enumerate system information such as finding IDs due to different messages for existing and non existing finding IDs.


Impact

Get all existing findings in the system.


Recommendation

Show the same response for existing and non-existing findings.


Threat

External attacker with access to integrates.


Expected Remediation Time

60 minutes.


Score 4.0

Default score using CVSS 4.0. It may change depending on the context of the src.

Base 4.0

  • Attack vector: N
  • Attack complexity: L
  • Attack Requirements: N
  • Privileges required: L
  • User interaction: N
  • Confidentiality (VC): L
  • Integrity (VI): N
  • Availability (VA): N
  • Confidentiality (SC): N
  • Integrity (SI): N
  • Availability (SA): N

Threat 4.0

  • Exploit maturity: X

Requirements


Fixes


Last updated

2024/02/20