Identity
CyberArk · 6 CVEs
CVE-2024-42340
HIGH
CyberArk - CWE-602: Client-Side Enforcement of Server-Side Security
Aug 25, 2024
CVE-2024-42339
MEDIUM
CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Aug 25, 2024
CVE-2024-42338
MEDIUM
CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Aug 25, 2024
CVE-2024-42337
MEDIUM
CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Aug 25, 2024
CVE-2022-22700
MEDIUM
CyberArk Identity versions up to and including 22.1 in the 'StartAuthentication' resource, exposes the response header…
Mar 3, 2022
CVE-2021-37151
MEDIUM
CyberArk Identity 21.5.131, when handling an invalid authentication attempt, sometimes reveals whether the username is…
Sep 1, 2021
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2024-42340 | CyberArk - CWE-602: Client-Side Enforcement of Server-Side Security | HIGH | 0.32% | Aug 25, 2024 |
| CVE-2024-42339 | CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor | MEDIUM | 0.29% | Aug 25, 2024 |
| CVE-2024-42338 | CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor | MEDIUM | 0.29% | Aug 25, 2024 |
| CVE-2024-42337 | CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor | MEDIUM | 0.31% | Aug 25, 2024 |
| CVE-2022-22700 | CyberArk Identity versions up to and including 22.1 in the 'StartAuthentication' resource, exposes the response header 'X-CFY-TX-TM'. In certain configurations… | MEDIUM | 1.11% | Mar 3, 2022 |
| CVE-2021-37151 | CyberArk Identity 21.5.131, when handling an invalid authentication attempt, sometimes reveals whether the username is valid. In certain authentication policy… | MEDIUM | 0.85% | Sep 1, 2021 |
Showing 1 to 6 of 6 CVEs