CVE Vulnerabilities

CVE-2020-25374

Insufficient Session Expiration

Published: Oct 28, 2020 | Modified: Nov 07, 2023
CVSS 3.x
2.6
LOW
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N
CVSS 2.x
2.1 LOW
AV:N/AC:H/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

CyberArk Privileged Session Manager (PSM) 10.9.0.15 allows attackers to discover internal pathnames by reading an error popup message after two hours of idle time.

Weakness

According to WASC, “Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization.”

Affected Software

Name Vendor Start Version End Version
Privileged_session_manager Cyberark 10.9.0.15 (including) 10.9.0.15 (including)

Potential Mitigations

References