PT-2020-9977 · Harris · Harris Ormed Self Service
Jake Rawlins
+1
·
Published
2020-03-25
·
Updated
2021-07-21
·
CVE-2019-18626
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Harris Ormed Self Service versions prior to 2019.1.4
Description:
The issue allows an authenticated user to view W-2 forms belonging to other users via an arbitrary
empNo value to the "ORMEDMIS/Data/PY/T4W2Service.svc/RetrieveW2EntriesForEmployee" URI, thus exposing sensitive information including employee tax information, social security numbers, home addresses, and more.Recommendations:
For versions prior to 2019.1.4, update to version 2019.1.4 or later to resolve the issue.
As a temporary workaround, consider restricting access to the "ORMEDMIS/Data/PY/T4W2Service.svc/RetrieveW2EntriesForEmployee" URI to minimize the risk of exploitation.
Avoid using arbitrary
empNo values in the affected URI until the issue is resolved.Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Harris Ormed Self Service