Back

MEDIUM

CyberArk Identity 21.5.131, when handling an invalid authentication attempt, sometimes reveals whether the username is valid

Published Sep 1, 2021

Description

CyberArk Identity 21.5.131, when handling an invalid authentication attempt, sometimes reveals whether the username is valid. In certain authentication policy configurations with MFA, the API response length can be used to differentiate between a valid user and an invalid one (aka Username Enumeration). Response differentiation enables attackers to enumerate usernames of valid application users. Attackers can use this information to leverage brute-force and dictionary attacks in order to discover valid account information such as passwords.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner INCD
Published Sep 1, 2021
Updated Aug 4, 2024
Reserved Jul 21, 2021
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner INCD
Published Sep 1, 2021
Updated Aug 4, 2024
Exploited since n/a
EUVD-2021-23725