CVE-2022-22700: Medium severity cyberark identity vulnerability
CyberArk Identity versions up to and including 22.1 in the 'StartAuthentication' resource, exposes the response header 'X-CFY-TX-TM'. In certain configurations, that response header contains different, predictable value ranges which can be used to determine whether a user exists in the tenant.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-22700.
What is the severity level of CVE-2022-22700?
The severity level of CVE-2022-22700 is medium with a score of 5.3.
How does CVE-2022-22700 affect CyberArk Identity?
CVE-2022-22700 affects CyberArk Identity versions up to and including 22.1 in the 'StartAuthentication' resource.
What is the exposure caused by CVE-2022-22700?
CVE-2022-22700 exposes the response header 'X-CFY-TX-TM' in certain configurations.
How can CVE-2022-22700 be used to determine if a user exists in the tenant?
CVE-2022-22700 can be used to determine if a user exists in the tenant by analyzing the different, predictable value ranges in the 'X-CFY-TX-TM' response header.