Sysaid API User Enumeration - Attacker sending requests to specific api path without any authorization before 21.3.60 version could get users names from the LDAP server.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Application_programming_interface | Sysaid | * | 21.3.60 (excluding) |
References