Executive brief
CBK Soft enVision, a document and process management system, contains a vulnerability that allows unauthorized individuals to identify valid user accounts and access sensitive personal information. By observing differences in how the system responds to various requests, an attacker can map out the user base, which is often a precursor to more targeted attacks or data theft. This flaw could lead to the exposure of private employee or customer data and compromise the overall security of the organization's identity management.
Technical details
CBK Soft enVision versions prior to 250566 are affected by an observable discrepancy vulnerability (CWE-203) and sensitive information disclosure (CWE-200, CWE-359). The flaw allows an unauthenticated remote attacker to perform account footprinting by analyzing differences in application responses. This can lead to the exposure of private personal information and the identification of valid system users. The vulnerability is exploitable over the network without user interaction. Users are advised to update to version 250566 or later to mitigate these risks.
Affected products
- CBK Soft enVision before 250566
Timeline
- 2025-10-24: advisory: Initial disclosure by TR-CERT (USOM)