Vulnerability in CyberArk Identity Exposing User Existence
CVE-2022-22700

5.3MEDIUM

Key Information:

Vendor

Cyberark

Vendor
CVE Published:
3 March 2022

What is CVE-2022-22700?

CyberArk Identity, up to version 22.1, contains a vulnerability in the 'StartAuthentication' resource that inadvertently exposes the response header 'X-CFY-TX-TM'. In certain configurations, this header may reveal predictable values which could potentially be exploited to ascertain whether a specific user exists within the tenant. This flaw could lead to unauthorized access or enumeration of users, highlighting the importance of securing response headers to maintain user privacy and security.

Affected Version(s)

CyberArk Identity 22.1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2022-22700 : Vulnerability in CyberArk Identity Exposing User Existence