CVE-2020-25374

LOW

CyberArk Privileged Session Manager 10.9.0.15 - Full Path Disclosure via Error Popup

Title source: llm
STIX 2.1

Description

CyberArk Privileged Session Manager (PSM) 10.9.0.15 allows attackers to discover internal pathnames by reading an error popup message after two hours of idle time.

Scores

CVSS v3 2.6
EPSS 0.0059
EPSS Percentile 43.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N

Details

CWE
CWE-613
Status published
Products (1)
cyberark/privileged_session_manager 10.9.0.15
Published Oct 28, 2020
Tracked Since Feb 18, 2026