Vulnerabilities
Vulnerable Software
Tenable:  >> Identity Exposure  Security Vulnerabilities
Tenable Identity Exposure contains multiple unauthenticated API endpoints under /w/api/* that expose sensitive application configuration data including cleartext LDAP credentials, SAML configuration, user accounts, and directory settings to unauthenticated remote attackers. Affected responses are served with Cache-Control: public headers and without Vary: Cookie, allowing reverse proxies and CDNs to cache and serve sensitive data to unauthenticated users even after authentication is applied.
CVSS Score
8.7
EPSS Score
0.006
Published
2026-06-23
A formula injection vulnerability exists in Tenable Identity Exposure where an authenticated remote attacker with administrative privileges could manipulate application form fields in order to trick another administrator into executing CSV payloads. - CVE-2024-3232
CVSS Score
7.6
EPSS Score
0.005
Published
2024-07-16
A DLL injection vulnerability exists where an authenticated, low-privileged local attacker could modify application files on the TIE Secure Relay host, which could allow for overriding of the configuration and running of new Secure Relay services.
CVSS Score
7.3
EPSS Score
0.003
Published
2024-02-23


Contact Us

Shodan ® - All rights reserved