CVE-2022-23342: Medium severity hyland onbase vulnerability
The Hyland Onbase Application Server releases prior to 20.3.58.1000 and OnBase releases 21.1.1.1000 through 21.1.15.1000 are vulnerable to a username enumeration vulnerability. An attacker can obtain valid users based on the response returned for invalid and valid users by sending a POST login request to the /mobilebroker/ServiceToBroker.svc/Json/Connect endpoint. This can lead to user enumeration against the underlying Active Directory integrated systems.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-23342?
CVE-2022-23342 has a high severity due to its potential to allow attackers to enumerate valid usernames.
How do I fix CVE-2022-23342?
To fix CVE-2022-23342, upgrade to Hyland OnBase Application Server version 20.3.58.1000 or higher, or 21.1.15.1000 or higher.
What is a username enumeration vulnerability as seen in CVE-2022-23342?
A username enumeration vulnerability allows attackers to differentiate between valid and invalid usernames based on response behavior during the login process.
Which versions of Hyland OnBase are affected by CVE-2022-23342?
CVE-2022-23342 affects Hyland OnBase versions prior to 20.3.58.1000 and versions between 21.1.1.1000 and 21.1.15.1000.
Can CVE-2022-23342 lead to further attacks beyond username enumeration?
Yes, successful username enumeration can facilitate targeted attacks such as phishing or brute-force attacks on user accounts.