Vulnerability in CyberArk Identity Exposing User Existence
CVE-2022-22700
5.3MEDIUM
What is CVE-2022-22700?
CyberArk Identity, up to version 22.1, contains a vulnerability in the 'StartAuthentication' resource that inadvertently exposes the response header 'X-CFY-TX-TM'. In certain configurations, this header may reveal predictable values which could potentially be exploited to ascertain whether a specific user exists within the tenant. This flaw could lead to unauthorized access or enumeration of users, highlighting the importance of securing response headers to maintain user privacy and security.
Affected Version(s)
CyberArk Identity 22.1
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved