CyberSec.Space Logo
Back to CVE Browser

CVE-2019-7442

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0920%
EPSS Percentile38.48th
PublishedMay 8, 2019
Last ModifiedNov 21, 2024

Vulnerability Description

An XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault <=10.7 allows remote attackers to read arbitrary files or potentially bypass authentication via a crafted DTD in the SAML authentication system.

Affected Platforms (CPE)

πŸ“¦
Cyberark

Enterprise Password Vault

<= 10.7

References & Advisories

Related Vulnerabilities