漏洞标题
CyberArk Endpoint Privilege Manager中的密码更改机制缺乏速率限制
漏洞描述信息
应用程序未限制用户操作的数量或频率,例如接收请求的数量。在 `/EPMUI/VfManager.asmx/ChangePassword` 端点,可能对当前使用的密码进行暴力破解攻击。
此问题影响 CyberArk Endpoint Privilege Manager SaaS 版本 24.7.1。其他版本的状态未知。经过多次尝试联系厂商,我们未收到任何回复。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
漏洞类别
过多认证尝试的限制不恰当
漏洞标题
Lack of rate-limiting in password change mechanism in CyberArk Endpoint Privilege Manager
漏洞描述信息
Application does not limit the number or frequency of user interactions, such as the number of incoming requests. At the "/EPMUI/VfManager.asmx/ChangePassword" endpoint it is possible to perform a brute force attack on the current password in use.
This issue affects CyberArk Endpoint Privilege Manager in SaaS version 24.7.1. The status of other versions is unknown. After multiple attempts to contact the vendor we did not receive any answer.
CVSS信息
N/A
漏洞类别
不加限制或调节的资源分配