vendor:
CA Privileged Access Manager
by:
Peter Lapp
8.8
CVSS
HIGH
Remote Command Execution
78
CWE
Product Name: CA Privileged Access Manager
Affected Version From: 2.8.2
Affected Version To: 2.8.2
Patch Exists: YES
Related CWE: CVE-2018-9021 and CVE-2018-9022
CPE: a:broadcom:ca_privileged_access_manager:2.8.2
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: v2.8.2
2019
Broadcom CA Privilged Access Manager 2.8.2 – Remote Command Execution
A vulnerability in Broadcom CA Privileged Access Manager (PAM) 2.8.2 allows an unauthenticated attacker to execute arbitrary commands on the underlying operating system. This vulnerability is due to insufficient input validation of user-supplied data. An attacker can exploit this vulnerability by sending a crafted HTTP request to the vulnerable application. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the underlying operating system.
Mitigation:
Upgrade to the latest version of Broadcom CA Privileged Access Manager (PAM) 2.8.2 or later.