Vulnerability Description
In CyberArk Viewfinity 5.5.10.95 and 6.x before 6.1.1.220, a low privilege user can escalate to an administrative user via a bug within the "add printer" option.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cyberark | Viewfinity | >= 6.0, < 6.1.1.220 |
References
- http://lp.cyberark.com/rs/316-CZP-275/images/ds-Viewfinity-102315-web.pdfProduct
- https://www.exploit-db.com/exploits/42319ExploitThird Party AdvisoryVDB Entry
- http://lp.cyberark.com/rs/316-CZP-275/images/ds-Viewfinity-102315-web.pdfProduct
- https://www.exploit-db.com/exploits/42319ExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2017-11197?
CVE-2017-11197 is a vulnerability with a CVSS score of 7.8 (HIGH). In CyberArk Viewfinity 5.5.10.95 and 6.x before 6.1.1.220, a low privilege user can escalate to an administrative user via a bug within the "add printer" option.
How severe is CVE-2017-11197?
CVE-2017-11197 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-11197?
Check the references section above for vendor advisories and patch information. Affected products include: Cyberark Viewfinity.