Show filters
22 Total Results
Displaying 1-10 of 22
Sort by:
Attacker Value
High
CVE-2019-9627
Disclosure Date: March 08, 2019 (last updated November 27, 2024)
A buffer overflow in the kernel driver CybKernelTracker.sys in CyberArk Endpoint Privilege Manager versions prior to 10.7 allows an attacker (without Administrator privileges) to escalate privileges or crash the machine by loading an image, such as a DLL, with a long path.
0
Attacker Value
Unknown
CVE-2024-42340
Disclosure Date: August 25, 2024 (last updated August 31, 2024)
CyberArk - CWE-602: Client-Side Enforcement of Server-Side Security
0
Attacker Value
Unknown
CVE-2024-42339
Disclosure Date: August 25, 2024 (last updated August 31, 2024)
CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
0
Attacker Value
Unknown
CVE-2024-42338
Disclosure Date: August 25, 2024 (last updated August 31, 2024)
CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
0
Attacker Value
Unknown
CVE-2024-42337
Disclosure Date: August 25, 2024 (last updated August 31, 2024)
CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
0
Attacker Value
Unknown
CVE-2017-11197
Disclosure Date: May 03, 2023 (last updated October 08, 2023)
In CyberArk Viewfinity 5.5.10.95 and 6.x before 6.1.1.220, a low privilege user can escalate to an administrative user via a bug within the "add printer" option.
0
Attacker Value
Unknown
CVE-2022-22700
Disclosure Date: March 03, 2022 (last updated October 07, 2023)
CyberArk Identity versions up to and including 22.1 in the 'StartAuthentication' resource, exposes the response header 'X-CFY-TX-TM'. In certain configurations, that response header contains different, predictable value ranges which can be used to determine whether a user exists in the tenant.
0
Attacker Value
Unknown
CVE-2021-44049
Disclosure Date: January 15, 2022 (last updated October 07, 2023)
CyberArk Endpoint Privilege Manager (EPM) through 11.5.3.328 before 2021-12-20 allows a local user to gain elevated privileges via a Trojan horse Procmon64.exe in the user's Temp directory.
0
Attacker Value
Unknown
CVE-2021-31796
Disclosure Date: September 02, 2021 (last updated November 28, 2024)
An inadequate encryption vulnerability discovered in CyberArk Credential Provider before 12.1 may lead to Information Disclosure. An attacker may realistically have enough information that the number of possible keys (for a credential file) is only one, and the number is usually not higher than 2^36.
0
Attacker Value
Unknown
CVE-2021-31798
Disclosure Date: September 02, 2021 (last updated November 28, 2024)
The effective key space used to encrypt the cache in CyberArk Credential Provider prior to 12.1 has low entropy, and under certain conditions a local malicious user can obtain the plaintext of cache files.
0