Full Path Disclosure Vulnerability in CyberArk Privileged Session Manager
CVE-2020-25374
2.6LOW
What is CVE-2020-25374?
The CyberArk Privileged Session Manager version 10.9.0.15 is susceptible to a full path disclosure vulnerability. After two hours of inactivity, the system displays an error popup that reveals sensitive internal pathnames to the user, potentially allowing attackers to glean valuable information about the backend structure of the application. This can pose significant security risks if exploited, enabling attackers to navigate the system more effectively and identify further weaknesses. It's crucial for organizations to assess the impact of such vulnerabilities and apply appropriate mitigations.