vendor:
Enterprise Password Vault
by:
Redteam Pentesting
5.3
CVSS
MEDIUM
Information Disclosure
200
CWE
Product Name: Enterprise Password Vault
Affected Version From: < 9.7, < 10
Affected Version To: 9.7, 10
Patch Exists: YES
Related CWE: CVE-2018-9842
CPE: a:cyberark:enterprise_password_vault
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2017
Advisory: CyberArk Password Vault Memory Disclosure
Data in the CyberArk Password Vault may be accessed through a proprietary network protocol. While answering to a client's logon request, the vault discloses around 50 bytes of its memory to the client.
Mitigation:
Upgrade to the latest version of CyberArk Password Vault