CVE-2020-11847 Vulnerability Details
/
/
/
CVE-2020-11847 Metadata Quick Info
CVE Published: 21/08/2024 |
CVE Updated: 22/08/2024 |
CVE Year: 2020
Source: OpenText |
Vendor: OpenText |
Product: Privileged Access Manager
Status : PUBLISHED
CVE-2020-11847 Description
SSH authenticated user when access the PAM server can execute an OS command to gain the full system access using bash. This issue affects Privileged Access Manager before 3.7.0.1.
Metrics
CVSS Version: 3.1 |
Base Score: 8.2 HIGH
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
l➤ Exploitability Metrics:
Attack Vector (AV)* LOCAL
Attack Complexity (AC)* LOW
Privileges Required (PR)* LOW
User Interaction (UI)* REQUIRED
Scope (S)* CHANGED
l➤ Impact Metrics:
Confidentiality Impact (C)* HIGH
Integrity Impact (I)* HIGH
Availability Impact (A)* HIGH
Weakness Enumeration (CWE)
CWE-ID: CWE-78
CWE Name: CWE-78 Improper Neutralization of Special Elements used in an OS Command (
OS Command Injection
)
Source: OpenText
Common Attack Pattern Enumeration and Classification (CAPEC)
CAPEC-ID: CAPEC-122
CAPEC Description: CAPEC-122 Privilege Abuse
Source: NVD (National Vulnerability Database).