Vulnerabilities > CVE-2019-7442 - XXE vulnerability in Cyberark Enterprise Password Vault 10.6/10.7

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
cyberark
CWE-611
critical
exploit available

Summary

An XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault <=10.7 allows remote attackers to read arbitrary files or potentially bypass authentication via a crafted DTD in the SAML authentication system.

Vulnerable Configurations

Part Description Count
Application
Cyberark
2

Exploit-Db

idEDB-ID:46828
last seen2019-05-10
modified2019-05-10
published2019-05-10
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/46828
titleCyberArk Enterprise Password Vault 10.7 - XML External Entity Injection

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/152801/cyberarkepv107-xml.txt
idPACKETSTORM:152801
last seen2019-05-11
published2019-05-10
reporterMarcelo Toran
sourcehttps://packetstormsecurity.com/files/152801/CyberArk-Enterprise-Password-Vault-10.7-XML-External-Entity-Injection.html
titleCyberArk Enterprise Password Vault 10.7 XML External Entity Injection