CVE-2025-22271
March 5, 2025, 4:15 p.m.
None
No Score
Description
The application or its infrastructure allows for IP address spoofing by providing its own value in the "X-Forwarded-For" header. Thus, the action logging mechanism in the application loses accountability
This issue affects CyberArk Endpoint Privilege Manager in SaaS version 24.7.1. The status of other versions is unknown. After multiple attempts to contact the vendor we did not receive any answer.
Product(s) Impacted
Product | Versions |
---|---|
CyberArk Endpoint Privilege Manager |
|
Weaknesses
Common security weaknesses mapped to this vulnerability.
CWE-290
Authentication Bypass by Spoofing
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
Tags
Timeline
Published: Feb. 28, 2025, 1:15 p.m.
Last Modified: March 5, 2025, 4:15 p.m.
Last Modified: March 5, 2025, 4:15 p.m.
Status : Awaiting Analysis
CVE has been recently published to the CVE List and has been received by the NVD.
More infoSource
cvd@cert.pl
*Disclaimer: Some vulnerabilities do not have an associated CPE. To enhance the data, we use AI to infer CPEs based on CVE details. This is an automated process and might not always be accurate.