Impact
Deliena Secret Server (On‑Prem) contains a padding oracle that enables an unauthenticated user to trigger decryption or encryption with the server’s cryptographic keys. The flaw does not expose the key itself; instead, repeated oracle responses allow recovery of encrypted data or creation of valid ciphertext. This jeopardizes the confidentiality of stored secrets and credentials.
Affected Systems
The affected product is Delinea Secret Server (On‑Prem). The CNA recommends upgrading to version 12.2.7 or later to eliminate the issue. No further version range is specified in the advisory.
Risk and Exploitability
The CVSS score of 9.1 marks the vulnerability as critical. The EPSS score of <1 % indicates that exploitation is currently unlikely, and the flaw is not listed in CISA’s KEV catalog. The attack vector is an unauthenticated endpoint; an attacker with network access can send crafted requests to elicit oracle responses and gradually reconstruct encrypted information or forge ciphertext, all without needing prior credentials.
OpenCVE Enrichment