PT-2021-21325 · Sysaid · Sysaid

Published

2021-12-14

·

Updated

2022-07-12

·

CVE-2021-36721

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Sysaid versions prior to 21.3.60
Description The issue allows an attacker to send requests to a specific API path without authorization, potentially obtaining user names from the LDAP server.
Recommendations For versions prior to 21.3.60, update to version 21.3.60 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-36721

Affected Products

Sysaid