7.5
CVSSv2

CVE-2018-9021

Published: 18/06/2018 Updated: 13/04/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and previous versions allows remote malicious users to execute arbitrary commands with specially crafted requests.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

broadcom privileged access manager

Exploits

# Title: Broadcom CA Privilged Access Manager 282 - Remote Command Execution # Author: Peter Lapp # Date: 2019-12-05 # Vendor: techdocsbroadcomcom/us/product-content/recommended-reading/security-notices/ca20180614-01--security-notice-for-ca-privileged-access-managerhtml # CVE: CVE-2018-9021 and CVE-2018-9022 # Tested on: v282 import ...
Broadcom CA Privileged Access Manager version 282 suffers from a remote command execution vulnerability ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> CA20180614-01: Security Notice for CA Privileged Access Manager <!--X-Subject-Header-End--> <!--X-Head-of-Message--> ...