Description
An improper input validation vulnerability in CA Privileged Access Manager 2.4.4.4 and earlier allows remote attackers to execute arbitrary commands.
Affected products
- CA Technologies / CA Privileged Access Manager2.4.4.4 and earlier – 2.4.4.4 and earlier
References
- MISChttps://support.ca.com/us/product-content/recommended-reading/security-notices/ca20180614-01--security-notice-for-ca-privileged-access-manager.html
- EXPLOIThttp://packetstormsecurity.com/files/132809/Xceedium-Xsuite-Command-Injection-XSS-Traversal-Escalation.html
- VENDOR_ADVISORYhttp://www.modzero.ch/advisories/MZ-15-02-Xceedium-Xsuite.txt
- EXPLOIThttps://www.exploit-db.com/exploits/37708/