Metrics
Affected Vendors & Products
No reference.
Wed, 24 Dec 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Wed, 24 Dec 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Convercent Whistleblowing Platform Unauthenticated GetLegalEntity Endpoint Enables Customer Enumeration | |
| Metrics |
ssvc
|
Wed, 24 Dec 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Convercent Whistleblowing Platform operated by EQS Group exposes an unauthenticated API endpoint at /GetLegalEntity that returns internal customer legal-entity names based on a supplied searchText fragment. A remote unauthenticated attacker can query the endpoint using common legal-suffix terms to enumerate Convercent tenants, identifying organizations using the platform. This disclosure can facilitate targeted phishing, extortion, or other attacks against whistleblowing programs and reveals sensitive business relationships and compliance infrastructure. | This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it identified a vulnerability in a SaaS product that does not require user action. |
| Metrics |
cvssV4_0
|
cvssV4_0
|
Tue, 16 Dec 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Eqs
Eqs convercent Whistleblowing Platform |
|
| Vendors & Products |
Eqs
Eqs convercent Whistleblowing Platform |
Mon, 15 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 15 Dec 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Convercent Whistleblowing Platform operated by EQS Group exposes an unauthenticated API endpoint at /GetLegalEntity that returns internal customer legal-entity names based on a supplied searchText fragment. A remote unauthenticated attacker can query the endpoint using common legal-suffix terms to enumerate Convercent tenants, identifying organizations using the platform. This disclosure can facilitate targeted phishing, extortion, or other attacks against whistleblowing programs and reveals sensitive business relationships and compliance infrastructure. | |
| Title | Convercent Whistleblowing Platform Unauthenticated GetLegalEntity Endpoint Enables Customer Enumeration | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: REJECTED
Assigner: VulnCheck
Published: 2025-12-15T14:43:37.839Z
Updated: 2025-12-24T19:58:04.485Z
Reserved: 2025-04-15T19:15:22.599Z
Link: CVE-2025-34411
Updated:
Status : Rejected
Published: 2025-12-15T15:15:49.997
Modified: 2025-12-24T20:15:55.043
Link: CVE-2025-34411
No data.
ReportizFlow