Full Path Disclosure Vulnerability in CyberArk Privileged Session Manager
CVE-2020-25374

2.6LOW

Key Information:

Vendor

Cyberark

Vendor
CVE Published:
28 October 2020

What is CVE-2020-25374?

The CyberArk Privileged Session Manager version 10.9.0.15 is susceptible to a full path disclosure vulnerability. After two hours of inactivity, the system displays an error popup that reveals sensitive internal pathnames to the user, potentially allowing attackers to glean valuable information about the backend structure of the application. This can pose significant security risks if exploited, enabling attackers to navigate the system more effectively and identify further weaknesses. It's crucial for organizations to assess the impact of such vulnerabilities and apply appropriate mitigations.

References

CVSS V3.1

Score:
2.6
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.