Show filters
22 Total Results
Displaying 1-10 of 22
Sort by:
Attacker Value
High

CVE-2019-9627

Disclosure Date: March 08, 2019 (last updated November 27, 2024)
A buffer overflow in the kernel driver CybKernelTracker.sys in CyberArk Endpoint Privilege Manager versions prior to 10.7 allows an attacker (without Administrator privileges) to escalate privileges or crash the machine by loading an image, such as a DLL, with a long path.
Attacker Value
Unknown

CVE-2024-42340

Disclosure Date: August 25, 2024 (last updated August 31, 2024)
CyberArk - CWE-602: Client-Side Enforcement of Server-Side Security
Attacker Value
Unknown

CVE-2024-42339

Disclosure Date: August 25, 2024 (last updated August 31, 2024)
CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Attacker Value
Unknown

CVE-2024-42338

Disclosure Date: August 25, 2024 (last updated August 31, 2024)
CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Attacker Value
Unknown

CVE-2024-42337

Disclosure Date: August 25, 2024 (last updated August 31, 2024)
CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Attacker Value
Unknown

CVE-2017-11197

Disclosure Date: May 03, 2023 (last updated October 08, 2023)
In CyberArk Viewfinity 5.5.10.95 and 6.x before 6.1.1.220, a low privilege user can escalate to an administrative user via a bug within the "add printer" option.
Attacker Value
Unknown

CVE-2022-22700

Disclosure Date: March 03, 2022 (last updated October 07, 2023)
CyberArk Identity versions up to and including 22.1 in the 'StartAuthentication' resource, exposes the response header 'X-CFY-TX-TM'. In certain configurations, that response header contains different, predictable value ranges which can be used to determine whether a user exists in the tenant.
Attacker Value
Unknown

CVE-2021-44049

Disclosure Date: January 15, 2022 (last updated October 07, 2023)
CyberArk Endpoint Privilege Manager (EPM) through 11.5.3.328 before 2021-12-20 allows a local user to gain elevated privileges via a Trojan horse Procmon64.exe in the user's Temp directory.
Attacker Value
Unknown

CVE-2021-31796

Disclosure Date: September 02, 2021 (last updated November 28, 2024)
An inadequate encryption vulnerability discovered in CyberArk Credential Provider before 12.1 may lead to Information Disclosure. An attacker may realistically have enough information that the number of possible keys (for a credential file) is only one, and the number is usually not higher than 2^36.
Attacker Value
Unknown

CVE-2021-31798

Disclosure Date: September 02, 2021 (last updated November 28, 2024)
The effective key space used to encrypt the cache in CyberArk Credential Provider prior to 12.1 has low entropy, and under certain conditions a local malicious user can obtain the plaintext of cache files.