PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 does not properly address environment issues that can contribute to Host header injection.
2025-02-03T18:15:36.967
2025-03-14T15:06:01.630
Analyzed
CVSSv3.1: 4.2 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | cyberark | privileged_access_manager | < 14.4 | Yes |