First published: Mon Dec 13 2021(Updated: )
Sysaid API User Enumeration - Attacker sending requests to specific api path without any authorization before 21.3.60 version could get users names from the LDAP server.
Credit: cna@cyber.gov.il
Affected Software | Affected Version | How to fix |
---|---|---|
Sysaid Application Programming Interface | <21.3.60 |
Update to version 21.3.60
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-36721 is a vulnerability in the Sysaid Application Programming Interface (API) that allows an attacker to enumerate user names from the LDAP server without authorization.
CVE-2021-36721 affects the Sysaid API versions before 21.3.60, allowing unauthorized users to retrieve user names from the LDAP server.
CVE-2021-36721 has a severity value of 5.3, which is considered medium.
To fix CVE-2021-36721, you should update your Sysaid API to version 21.3.60 or later.
You can find more information about CVE-2021-36721 at https://www.gov.il/en/departments/faq/cve_advisories.