Privileged Access Manager
Vendor:
First CVE: Jun 18, 2018 · Active for 8 years
10
Total CVEs
More Total CVEs than 88% of tracked products
5.0
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
8.5
Avg CVSS
Higher Avg CVSS than 75% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Privileged Access Manager over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 18, 2018
8 years ago
Most Recent CVE
Feb 26, 2019
2,705 days ago
CVE Severity & Scoring
Privileged Access Manager10 CVEs
10%
40%
50%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None10 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low1 (10.0%)
High0 (0.0%)
None9 (90.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-9022CRITICAL An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary code or commands by poisoning a configuration | Jun 18, 2018 | 9.8 | 53 | NO | YES |
CVE-2018-9021CRITICAL An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary commands with specially crafted requests. | Jun 18, 2018 | 9.8 | 52 | NO | YES |
CVE-2015-4664CRITICAL An improper input validation vulnerability in CA Privileged Access Manager 2.4.4.4 and earlier allows remote attackers to execute arbitrary commands. | Jun 18, 2018 | 9.8 | 45 | NO | YES |
CVE-2018-9029CRITICAL An improper input validation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to conduct SQL injection attacks. | Jun 18, 2018 | 9.8 | 29 | NO | NO |
CVE-2018-9023HIGH An input validation vulnerability in CA Privileged Access Manager 2.x allows unprivileged users to execute arbitrary commands by passing specially crafted arguments to the update_c | Jun 18, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-9026HIGH A session fixation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to hijack user sessions with a specially crafted request. | Jun 18, 2018 | 7.5 | 24 | NO | NO |
CVE-2018-9025HIGH An input validation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to poison log files with specially crafted input. | Jun 18, 2018 | 7.5 | 24 | NO | NO |
CVE-2019-7392CRITICAL An improper authentication vulnerability in CA Privileged Access Manager 3.x Web-UI jk-manager and jk-status allows a remote attacker to gain sensitive information or alter configu | Feb 26, 2019 | 9.1 | 23 | NO | NO |
CVE-2018-9028HIGH Weak cryptography used for passwords in CA Privileged Access Manager 2.x reduces the complexity for password cracking. | Jun 18, 2018 | 7.5 | 23 | NO | NO |
CVE-2018-9024MEDIUM An improper authentication vulnerability in CA Privileged Access Manager 2.x allows attackers to spoof IP addresses in a log file. | Jun 18, 2018 | 5.3 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
30.0% of CVEs· 90th percentile
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Privileged Access Manager
Top CWEs
Versions
No cataloged versions.