CVE-2020-11847

S

SH authenticated user when access the PAM server can execute an OS command to gain the full system access using bash. This issue affects Privileged Access Manager before 3.7.0.1.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microfocus:netiq_privileged_access_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:netiq_privileged_access_manager:3.7:-:*:*:*:*:*:*

History

23 Aug 2024, 17:04

Type Values Removed Values Added
References () https://www.netiq.com/documentation/privileged-account-manager-37/npam_3701_releasenotes/data/npam_3701_releasenotes.html - () https://www.netiq.com/documentation/privileged-account-manager-37/npam_3701_releasenotes/data/npam_3701_releasenotes.html - Release Notes
CVSS v2 : unknown
v3 : 8.2
v2 : unknown
v3 : 7.8
Summary
  • (es) El usuario autenticado por SSH cuando accede al servidor PAM puede ejecutar un comando del sistema operativo para obtener acceso completo al sistema mediante bash. Este problema afecta a Privileged Access Manager anterior a 3.7.0.1.
CPE cpe:2.3:a:microfocus:netiq_privileged_access_manager:3.7:-:*:*:*:*:*:*
cpe:2.3:a:microfocus:netiq_privileged_access_manager:*:*:*:*:*:*:*:*
First Time Microfocus netiq Privileged Access Manager
Microfocus

21 Aug 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-21 14:15

Updated : 2024-08-23 17:04


NVD link : CVE-2020-11847

Mitre link : CVE-2020-11847

CVE.ORG link : CVE-2020-11847


JSON object : View

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')