CVE-2021-28250: High severity ca ehealth performance manager vulnerability
UNSUPPORTED WHEN ASSIGNED CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a setuid (and/or setgid) file. When a component is run as an argument of the runpicEhealth executable, the script code will be executed as the ehealth user. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28250?
CVE-2021-28250 has a medium severity rating due to the potential for privilege escalation.
How do I fix CVE-2021-28250?
To fix CVE-2021-28250, update CA eHealth Performance Manager to a version beyond 6.3.2.12.
What systems are affected by CVE-2021-28250?
CVE-2021-28250 affects CA eHealth Performance Manager versions up to and including 6.3.2.12.
What type of vulnerability is CVE-2021-28250?
CVE-2021-28250 is a privilege escalation vulnerability related to setuid and setgid files.
Can CVE-2021-28250 be exploited remotely?
CVE-2021-28250 could potentially allow local users to escalate privileges, but it is not a remote exploit.