SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-22853

While obtaining user ID, remote attackers can access sensitive data via a specific data packet, such as user’s login information, further causing the login function not to work.

MEDIUM 5.4EPSS 1.04%

Does this matter?

Lower severity and a low EPSS score (1.04%). Track it; it rarely justifies an emergency change on its own.

Description

The HR Portal of Soar Cloud System fails to manage access control. While obtaining user ID, remote attackers can access sensitive data via a specific data packet, such as user’s login information, further causing the login function not to work.

CVSS 3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
EPSS
1.04% probability · 62th percentile
CISA KEV
Not listed
Weakness
CWE-284
Affected
hr portal project/hr portal
Source
twcert@cert.org.tw

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.