[Japanese]

JVNDB-2011-000023

Password Vault Web Access vulnerable to cross-site scripting

Overview

Password Vault Web Access (PVWA) provided by Cyber-Ark Software, Ltd. contains a cross-site scripting vulnerability.

Password Vault Web Access (PVWA) is a module in the Privileged Identity Management Suite that allows access via a web portal. PVWA contains a cross-site scripting vulnerability.
CVSS Severity (What is CVSS?)

CVSS V2 Severity:
Base Metrics 4.0 (Medium) [IPA Score]
  • Access Vector: Network
  • Access Complexity: Low
  • Authentication: Single Instance
  • Confidentiality Impact: None
  • Integrity Impact: Partial
  • Availability Impact: None
Affected Products


Cyber-Ark Software
  • Password Vault Web Access v6.0 releases v6.0 patch #2 and earlier
  • Password Vault Web Access v5.5 releases v5.5 patch #4 and earlier
  • Password Vault Web Access PVWA v5.0 and earlier

Impact

An arbitrary script may be executed on the web browser of an user who is logged on.
Solution

[Apply a patch]
Apply the appropriate patch according to the information provided by the developer.
Vendor Information

Cyber-Ark Software
CWE (What is CWE?)

  1. Cross-site Scripting(CWE-79) [IPA Evaluation]
CVE (What is CVE?)

  1. CVE-2011-0459
References

  1. JVN : JVN#11424086
  2. National Vulnerability Database (NVD) : CVE-2011-0459
Revision History

  • [2011/04/08]
      Web page published