CVEs (6)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
CyberArk - CWE-602: Client-Side Enforcement of Server-Side Security |
CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor |
CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor |
CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor |
CyberArk Identity versions up to and including 22.1 in the 'StartAuthentication' resource, exposes the response header 'X-CFY-TX-TM'. In certain configurations, that response header contains different, predictable value...Show more |
CyberArk Identity 21.5.131, when handling an invalid authentication attempt, sometimes reveals whether the username is valid. In certain authentication policy configurations with MFA, the API response length can be used...Show more |