Início
Início
Tendências
Tendências
Vulnerabilidades
Vulnerabilidades
Notícias
Notícias
Pesquisadores
Pesquisadores
Por que dbugs?
Por que dbugs?
Configurações

Marcelo Torán

Pesquisador deNixu Corporation
#26412de 56,337
9.8CVSS total
Vulnerabilidades · 1
PT-2019-18615
9.8
2019-05-08
Cyberark · Cyberark Enterprise Password Vault · CVE-2019-7442
**Name of the Vulnerable Software and Affected Versions** CyberArk Enterprise Password Vault versions prior to 10.7 **Description** The issue is related to an XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault. This vulnerability allows remote attackers to read arbitrary files or potentially bypass authentication by using a crafted DTD in the SAML authentication system. **Recommendations** For versions prior to 10.7, update to version 10.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the SAML authentication system to minimize the risk of exploitation.