Automatic information enumeration - Corporate information
Description
It is possible to automatically enumerate system information such as finding IDs due to different messages for existing and non existing finding IDs.
Impact
Get all existing findings in the system.
Recommendation
Show the same response for existing and non-existing findings.
Threat
External attacker with access to integrates.
Expected Remediation Time
⏱️ 60 minutes.