Cyberark · Cyberark Enterprise Password Vault · CVE-2019-7442
**Name of the Vulnerable Software and Affected Versions**
CyberArk Enterprise Password Vault versions prior to 10.7
**Description**
The issue is related to an XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault. This vulnerability allows remote attackers to read arbitrary files or potentially bypass authentication by using a crafted DTD in the SAML authentication system.
**Recommendations**
For versions prior to 10.7, update to version 10.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the SAML authentication system to minimize the risk of exploitation.