CVE-2024-57967
PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 has potentially elevated privileges in LDAP mapping.
Severity
Medium 4.2
CVSS 3.1
Exploited
Not listed
EPSS
0.002
13.5th percentile
Discovered by
Not disclosed
Published
Feb 3, 2025
Assigned by mitre
Description
PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 has potentially elevated privileges in LDAP mapping.
Weakness: CWE-266
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | CyberArk Privileged Access Manager | Identity / IAM / MFA | affected-vendor |
Vendor-reported products (1)
- CyberArk · Privileged Access Manager