Saviynt Inc. develops cloud-based identity and access governance platforms serving enterprise environments, with its observed vulnerability exposure centered on the Enterprise Identity Cloud product. The durable signal reflects application-layer authorization and authentication weaknesses, specifically user-controlled authorization keys and weak password-recovery mechanisms that recur in identity-management systems. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Saviynt Inc. over time
Of all the CVEs published by Saviynt Inc. as a CNA, 0.0% affect products that Saviynt Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Saviynt Inc., 0.0% are self-published by Saviynt Inc. as a CNA.
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-23855CRITICAL An issue was discovered in Saviynt Enterprise Identity Cloud (EIC) 5.5 SP2.x. An authentication bypass in ECM/maintenance/forgotpasswordstep1 allows an unauthenticated user to rese | Jan 24, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-23856MEDIUM An issue was discovered in Saviynt Enterprise Identity Cloud (EIC) 5.5 SP2.x. An attacker can enumerate users by changing the id parameter, such as for the ECM/maintenance/forgotpa | Jan 24, 2022 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Saviynt Inc..
Media articles that mention a CVE ID that affects a product developed by Saviynt Inc. — matched by CVE ID, not by vendor name.