CVE-2018-9022: Critical severity Broadcom Privileged Access Manager vulnerability
Published Jun 18, 2018
·Updated
An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary code or commands by poisoning a configuration file.
Affected Software
1 affected component
Broadcom Privileged Access Manager<=2.8.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
CA Privileged Access Managerto a version that resolves this vulnerability.Fixed in 2.8.2
Event History
Jun 18, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionWeakness
Data Sourced
via NVD·06:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-9022?
CVE-2018-9022 is considered a critical vulnerability as it allows remote attackers to execute arbitrary code.
2
How do I fix CVE-2018-9022?
To fix CVE-2018-9022, upgrade CA Privileged Access Manager to version 2.8.3 or later.
3
What systems are affected by CVE-2018-9022?
CVE-2018-9022 affects CA Privileged Access Manager version 2.8.2 and earlier.
4
What type of vulnerability is CVE-2018-9022?
CVE-2018-9022 is an authentication bypass vulnerability.
5
Can CVE-2018-9022 be exploited remotely?
Yes, CVE-2018-9022 can be exploited remotely by attackers.