Impact
The vulnerability is caused by improper protection of sensitive configuration information in uniFLOW ULM Standalone. An attacker who has authenticated administrative privileges can retrieve confidential configuration details, specifically those relating to SMTP or LDAP integrations, through the ULM Remote User Interface. This disclosure enables potential credential compromise or further attacks, as the exposed settings may contain service credentials or addresses. The weakness is classified as CWE-522.
Affected Systems
The affected product is NT‑ware's uniFLOW ULM Standalone. No version specific data is listed in the advisory, and deployments that are connected to uniFLOW Server or uniFLOW Online are explicitly excluded from impact.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity, while the EPSS score of less than 1% shows that the likelihood of exploitation is very low. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated administrator, so the risk depends largely on internal access controls. The potential impact is limited to disclosure of configuration data and does not affect authentication or execution of arbitrary code.
OpenCVE Enrichment