id: oipm-detect info: name: One Identity Password Manager Detection author: nodauf severity: info description: One Identity Password Manager is a secure password manager that gives enterprises control over password management, policies, and automated reset functions. remediation: Ensure proper access. reference: - https://www.oneidentity.com/techbrief/security-guide-for-password-manager821177/ classification: cwe-id: CWE-200 cpe: cpe:2.3:a:oneidentity:password_manager:*:*:*:*:*:*:*:* metadata: max-request: 1 vendor: oneidentity product: password_manager tags: panel,oneidentity http: - method: GET path: - '{{BaseURL}}/PMUser/' matchers: - type: word words: - "One Identity Password Manager" # digest: 4a0a00473045022100a942d91845e68028ccc7631ccfc503b883427fa400420fc3b4285ccc41e9474b022025e99e695d0d33e8f18f7fdb9f72a4398bf21a926643331f069cca175b676f4f:922c64590222798bb761d5b6d8e72950