Full Report
CERT Polska has received a report about 5 vulnerabilities (from CVE-2025-22270 to CVE-2025-22274) found in CyberArk Endpoint Privilege Manager software.
Analysis Summary
This summary aggregates the five vulnerabilities reported against CyberArk Endpoint Privilege Manager by CERT Polska. Note that the severity scores (CVSS) were not provided in the source text, so they are marked as "N/A".
---
# Vulnerability: Multiple Flaws in CyberArk Endpoint Privilege Manager (CVE-2025-22270 to CVE-2025-22274)
## CVE Details
| CVE ID | CVSS Score | Severity | CWE |
| :--- | :--- | :--- | :--- |
| CVE-2025-22270 | N/A | N/A | CWE-79 (XSS) |
| CVE-2025-22271 | N/A | N/A | CWE-290 (Auth Bypass by Spoofing) |
| CVE-2025-22272 | N/A | N/A | CWE-79 (XSS) |
| CVE-2025-22273 | N/A | N/A | CWE-770 (Resource Exhaustion) |
| CVE-2025-22274 | N/A | N/A | CWE-XXX (Improper Neutralization...) |
## Affected Systems
- **Products:** CyberArk Endpoint Privilege Manager
- **Versions:** 24.7.1 (All five vulnerabilities affect this version)
- **Configurations:** Not specified, presumed default installations.
## Vulnerability Description
Five distinct vulnerabilities affecting CyberArk Endpoint Privilege Manager version 24.7.1 were reported:
1. **CVE-2025-22270 & CVE-2025-22272:** Cross-Site Scripting (XSS) vulnerabilities due to improper neutralization of input during web page generation (CWE-79).
2. **CVE-2025-22271:** An Authentication Bypass by Spoofing vulnerability (CWE-290).
3. **CVE-2025-22273:** A vulnerability related to the allocation of resources without limits or throttling (CWE-770), suggesting a potential Denial of Service vector.
4. **CVE-2025-22274:** A flaw involving improper neutralization of script-related input (details incomplete in the source).
## Exploitation
- **Status:** Unknown. The report does not specify if these vulnerabilities are being exploited in the wild or if Proof-of-Concepts (PoCs) are publicly available.
- **Complexity:** Unknown.
- **Attack Vector:** Unknown, though XSS and Authentication Bypass suggest potential remote or client-side vectors.
## Impact
*Note: Assumed impact based on CWE descriptions, as explicit impact ratings were not provided.*
- **Confidentiality:** Moderate potential (due to XSS storing/stealing session data).
- **Integrity:** Moderate potential (due to XSS manipulating application content or Auth Bypass).
- **Availability:** Potential impact due to resource exhaustion (CVE-2025-22273).
## Remediation
### Patches
No specific patch versions or advisory links containing the fix details were provided in the input source. Users must consult official CyberArk advisories for updated versions that address CVE-2025-22270 through CVE-2025-22274.
### Workarounds
No specific workarounds were provided in the source material.
## Detection
- Detection mechanisms are not detailed in the source. Security operations teams should monitor network traffic and application logs for anomalous inputs characteristic of XSS attempts or unusual resource consumption patterns related to the product.
## References
- Vendor advisories: None explicitly available in the provided text.
- Relevant links:
- CERT Polska: hxxps://cert.pl/en/news/