Show filters
14 Total Results
Displaying 1-10 of 14
Sort by:
Attacker Value
Unknown

CVE-2024-12111

Disclosure Date: December 19, 2024 (last updated December 20, 2024)
In a specific scenario a LDAP user can abuse the authentication process in OpenText Privileged Access Manager that allows authentication bypass. This issue affects Privileged Access Manager version 23.3(4.4); 24.3(4.5)
0
Attacker Value
Unknown

CVE-2020-11847

Disclosure Date: August 21, 2024 (last updated August 24, 2024)
SSH authenticated user when access the PAM server can execute an OS command to gain the full system access using bash. This issue affects Privileged Access Manager before 3.7.0.1.
Attacker Value
Unknown

CVE-2020-11846

Disclosure Date: August 21, 2024 (last updated August 24, 2024)
A vulnerability found in OpenText Privileged Access Manager that issues a token. on successful issuance of the token, a cookie gets set that allows unrestricted access to all the application resources. This issue affects Privileged Access Manager before 3.7.0.1.
Attacker Value
Unknown

CVE-2019-7392

Disclosure Date: February 26, 2019 (last updated November 27, 2024)
An improper authentication vulnerability in CA Privileged Access Manager 3.x Web-UI jk-manager and jk-status allows a remote attacker to gain sensitive information or alter configuration.
0
Attacker Value
Unknown

CVE-2015-4664

Disclosure Date: June 18, 2018 (last updated November 26, 2024)
An improper input validation vulnerability in CA Privileged Access Manager 2.4.4.4 and earlier allows remote attackers to execute arbitrary commands.
0
Attacker Value
Unknown

CVE-2018-9026

Disclosure Date: June 18, 2018 (last updated November 26, 2024)
A session fixation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to hijack user sessions with a specially crafted request.
0
Attacker Value
Unknown

CVE-2018-9021

Disclosure Date: June 18, 2018 (last updated November 26, 2024)
An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary commands with specially crafted requests.
Attacker Value
Unknown

CVE-2018-9023

Disclosure Date: June 18, 2018 (last updated November 26, 2024)
An input validation vulnerability in CA Privileged Access Manager 2.x allows unprivileged users to execute arbitrary commands by passing specially crafted arguments to the update_crld script.
0
Attacker Value
Unknown

CVE-2018-9029

Disclosure Date: June 18, 2018 (last updated November 26, 2024)
An improper input validation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to conduct SQL injection attacks.
0
Attacker Value
Unknown

CVE-2018-9022

Disclosure Date: June 18, 2018 (last updated November 26, 2024)
An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary code or commands by poisoning a configuration file.