Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to User enumeration. The Systeam application is an ERP system that uses a mixed architecture based on SaaS tenant and user management, and on-premise database and web application counterparts. This issue occurs during the password recovery procedure for a given user, where a difference in messages could allow an attacker to determine if the given user is valid or not, enabling a brute force attack with valid users.
                
            Metrics
Affected Vendors & Products
Advisories
    | Source | ID | Title | 
|---|---|---|
  EUVD | 
                EUVD-2021-31677 | Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to User enumeration. The Systeam application is an ERP system that uses a mixed architecture based on SaaS tenant and user management, and on-premise database and web application counterparts. This issue occurs during the password recovery procedure for a given user, where a difference in messages could allow an attacker to determine if the given user is valid or not, enabling a brute force attack with valid users. | 
Fixes
    Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
        | Link | Providers | 
|---|---|
| https://www.systeam.com.br/cve/userenum-2-en.txt | 
                     | 
            
History
                    No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T04:32:13.464Z
Reserved: 2021-12-13T00:00:00
Link: CVE-2021-44875
No data.
Status : Modified
Published: 2021-12-21T17:15:08.513
Modified: 2024-11-21T06:31:38.460
Link: CVE-2021-44875
No data.
                        OpenCVE Enrichment
                    No data.
 EUVD