CVE-2024-25651

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/03/2024
Last modified:
14/10/2025

Description

User enumeration can occur in the Authentication REST API in Delinea PAM Secret Server 11.4. This allows a remote attacker to determine whether a user is valid because of a difference in responses from the /oauth2/token endpoint.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:delinea:secret_server:11.4.000000:*:*:*:on-premises:*:*:*