VulnerabilityModified
CVE-2018-9022
An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary code or commands by poisoning a configuration file.
CRITICAL 9.8EPSS 12.8%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 12.8%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary code or commands by poisoning a configuration file.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 12.80% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-269
- Affected
- broadcom/privileged access manager
- Source
- vuln@ca.com
References
- http://packetstormsecurity.com/files/155576/Broadcom-CA-Privileged-Access-Manager-2.8.2-Remote-Command-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/104496Third Party Advisory, VDB Entry
- https://support.ca.com/us/product-content/recommended-reading/security-notices/ca20180614-01--security-notice-for-ca-privileged-access-manager.htmlBroken Link
- http://packetstormsecurity.com/files/155576/Broadcom-CA-Privileged-Access-Manager-2.8.2-Remote-Command-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/104496Third Party Advisory, VDB Entry
- https://support.ca.com/us/product-content/recommended-reading/security-notices/ca20180614-01--security-notice-for-ca-privileged-access-manager.htmlBroken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.