First published: Mon Jun 18 2018(Updated: )
Weak cryptography used for passwords in CA Privileged Access Manager 2.x reduces the complexity for password cracking.
Credit: vuln@ca.com
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom Privileged Access Manager | >=2.0.0<3.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-9028 is considered a high-severity vulnerability due to weak cryptography used for password storage.
To fix CVE-2018-9028, upgrade to CA Privileged Access Manager version 3.0.0 or later where the cryptographic methods have been improved.
CVE-2018-9028 affects versions 2.0.0 to 2.x.x of Broadcom's Privileged Access Manager.
CVE-2018-9028 increases the risk of password cracking, potentially exposing sensitive information.
There are no recommended workarounds for CVE-2018-9028, so upgrading to a secure version is the best course of action.