CVE-2024-57967: Medium severity cyberark privileged access manager vulnerability
Published Feb 3, 2025
·Updated
PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 has potentially elevated privileges in LDAP mapping.
Affected Software
1 affected component
CyberArk Privileged Access Manager Self-Hosted<14.4
Event History
Feb 3, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-57967?
CVE-2024-57967 is classified with a high severity due to the potential for elevated privileges in LDAP mapping within CyberArk Privileged Access Manager.
2
How do I fix CVE-2024-57967?
To fix CVE-2024-57967, upgrade to CyberArk Privileged Access Manager Self-Hosted version 14.4 or later.
3
What are the potential impacts of CVE-2024-57967?
The potential impacts of CVE-2024-57967 include unauthorized access and potential privilege escalation in the system.
4
Which versions of CyberArk are affected by CVE-2024-57967?
CVE-2024-57967 affects CyberArk Privileged Access Manager Self-Hosted versions prior to 14.4.
5
Is there a workaround for CVE-2024-57967?
There are currently no official workarounds for CVE-2024-57967, hence upgrading is recommended.