Identity
by Cyber Ark
CVEs (6)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-42340 | Hig | 0.54 | 8.3 | 0.00 | Aug 25, 2024 | CyberArk - CWE-602: Client-Side Enforcement of Server-Side Security | ||
| CVE-2022-22700 | Med | 0.35 | 5.3 | 0.01 | Mar 3, 2022 | CyberArk Identity versions up to and including 22.1 in the 'StartAuthentication' resource, exposes the response header 'X-CFY-TX-TM'. In certain configurations, that response header contains different, predictable value ranges which can be used to determine whether a user exists… | ||
| CVE-2021-37151 | Med | 0.35 | 5.3 | 0.01 | Sep 1, 2021 | CyberArk Identity 21.5.131, when handling an invalid authentication attempt, sometimes reveals whether the username is valid. In certain authentication policy configurations with MFA, the API response length can be used to differentiate between a valid user and an invalid one… | ||
| CVE-2024-42339 | Med | 0.28 | 4.3 | 0.00 | Aug 25, 2024 | CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor | ||
| CVE-2024-42338 | Med | 0.28 | 4.3 | 0.00 | Aug 25, 2024 | CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor | ||
| CVE-2024-42337 | Med | 0.28 | 4.3 | 0.00 | Aug 25, 2024 | CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor |
- risk 0.54cvss 8.3epss 0.00
CyberArk - CWE-602: Client-Side Enforcement of Server-Side Security
- risk 0.35cvss 5.3epss 0.01
CyberArk Identity versions up to and including 22.1 in the 'StartAuthentication' resource, exposes the response header 'X-CFY-TX-TM'. In certain configurations, that response header contains different, predictable value ranges which can be used to determine whether a user exists…
- risk 0.35cvss 5.3epss 0.01
CyberArk Identity 21.5.131, when handling an invalid authentication attempt, sometimes reveals whether the username is valid. In certain authentication policy configurations with MFA, the API response length can be used to differentiate between a valid user and an invalid one…
- risk 0.28cvss 4.3epss 0.00
CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- risk 0.28cvss 4.3epss 0.00
CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- risk 0.28cvss 4.3epss 0.00
CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor