CVE-2018-9025: Input Validation
Published Jun 18, 2018
·Updated
An input validation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to poison log files with specially crafted input.
Affected Software
1 affected component
Broadcom Privileged Access Manager>=2.0.0<3.0.0
Event History
Jun 18, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionWeakness
Data Sourced
via NVD·06:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-9025?
CVE-2018-9025 has been classified as a medium severity vulnerability due to its input validation issues that can lead to log file poisoning.
2
How do I fix CVE-2018-9025?
To fix CVE-2018-9025, update CA Privileged Access Manager to version 3.0.0 or later, as versions 2.x are vulnerable.
3
What type of attack does CVE-2018-9025 enable?
CVE-2018-9025 allows remote attackers to poison log files through specially crafted input.
4
What are the affected versions in CVE-2018-9025?
CVE-2018-9025 affects CA Privileged Access Manager versions between 2.0.0 and 3.0.0.
5
Is user authentication required to exploit CVE-2018-9025?
Exploitation of CVE-2018-9025 can occur without user authentication, making it more critical.