Under certain circumstances a CCURE Portal user could enumerate user accounts in CCURE 9000 version 2.90 and prior versions.CreditsKim Syversen and Mathias Kjølleberg Førland reported this vulnerability to Johnson ControlsReferenceshttps://www.johnsoncontrols.com/cyber-solutions/security-advisorieshttps://www.cisa.gov/uscert/ics/advisories/icsa-22-284-03