CVE-2025-5141: Core Privileged Access Manager (BoKS) Leakage of Sensitive Data via the Cache
A binary in the BoKS Server Agent component of Fortra's Core Privileged Access Manager (BoKS) on versions 7.2.0 (up to 7.2.0.17), 8.1.0 (up to 8.1.0.22), 8.1.1 (up to 8.1.1.7), 9.0.0 (up to 9.0.0.1) and also legacy tar installs of BoKS 7.2 without hotfix #0474 on Linux, AIX, and Solaris allows low privilege local users to dump data from the cache.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5141?
CVE-2025-5141 has been classified with a high severity due to the potential impact on system security and privileged access.
How do I fix CVE-2025-5141?
To mitigate CVE-2025-5141, upgrade to BoKS Server Agent versions beyond 7.2.0.17, 8.1.0.22, 8.1.1.7, and 9.0.0.1 or apply the appropriate hotfix if on a legacy version.
What is affected by CVE-2025-5141?
CVE-2025-5141 affects Fortra's Core Privileged Access Manager, specifically versions 7.2.0 up to 7.2.0.17, 8.1.0 up to 8.1.0.22, 8.1.1 up to 8.1.1.7, and 9.0.0 up to 9.0.0.1.
What platforms are impacted by CVE-2025-5141?
CVE-2025-5141 impacts systems running Linux, AIX, and Solaris where BoKS Server Agent is installed.
Is there a workaround for CVE-2025-5141?
There are no reliable workarounds for CVE-2025-5141; the recommended action is to promptly update to the fixed versions.