CVE-2018-9022
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 20%
from disclosure to weapon535 days
Published on NVDJun 18
1st PoC+535d
exploitation probability
20%top 3% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary code or commands by poisoning a configuration file.
Affected products
CA Technologies · CA Privileged Access Managerpublic PoCs found — 2✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/47748cve_referencepacketstormsecurity.com/files/155576/Broadcom-CA-Privileged-Access-Manager-2.8.2-Remote-Command-Execution.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/155576/Broadcom-CA-Privileged-Access-Manager-2.8.2-Remote-Command-Execution.htmlhttps://support.ca.com/us/product-content/recommended-reading/security-notices/ca20180614-01--security-notice-for-ca-privileged-access-manager.htmlhttp://www.securityfocus.com/bid/104496