Known vulnerabilities in Privileged Access Manager

Software CPE: cpe:2.3:a:ca_technologies:privileged_access_manager:*:*:*:*:*:*:*:*
Total vulnerabilities: 15
Public exploits: 6
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Privileged Access Manager Privileged Access Manager is affected by 15 known vulnerabilities: 1 high, 14 low Critical High Medium Low

Vulnerabilities (15)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU13358 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2018-9029
CWE-89 Low
No
No
3.0.0 15.06.2018 SB2018061508
#VU13357 - Exposure of sensitive information to an unauthorized actor
CVE-2018-9028
CWE-200 Low
No
No
3.0.0 15.06.2018 SB2018061508
#VU13356 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2015-4668
CWE-601 Low
Available
No
3.0.0 15.06.2018 SB2018061508
#VU13355 - Insufficiently Protected Credentials
CVE-2015-4669
CWE-522 Low
Available
No
3.0.0 15.06.2018 SB2018061508
#VU13354 - Use of Hard-coded Credentials
CVE-2015-4667
CWE-798 Low
Available
No
3.0.0 15.06.2018 SB2018061508
#VU13353 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2015-4666
CWE-22 Low
Available
No
3.0.0 15.06.2018 SB2018061508
#VU13352 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2015-4665
CWE-79 Low
Available
No
3.0.0 15.06.2018 SB2018061508
#VU13351 - Command injection
CVE-2015-4664
CWE-77 Low
Available
No
3.0.0 15.06.2018 SB2018061508
#VU13350 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-9027
CWE-79 Low
No
No
3.0.0 15.06.2018 SB2018061508
#VU13349 - Session Fixation
CVE-2018-9026
CWE-384 Low
No
No
3.0.0 15.06.2018 SB2018061508
#VU13348 - Permissions, Privileges, and Access Controls
CVE-2018-9025
CWE-264 Low
No
No
3.0.0 15.06.2018 SB2018061508
#VU13347 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2018-9024
CWE-451 Low
No
No
3.0.0 15.06.2018 SB2018061508
#VU13346 - Permissions, Privileges, and Access Controls
CVE-2018-9023
CWE-264 Low
No
No
3.0.0 15.06.2018 SB2018061508
#VU13345 - Permissions, Privileges, and Access Controls
CVE-2018-9022
CWE-264 High
No
No
3.0.0 15.06.2018 SB2018061508
#VU13344 - Command injection
CVE-2018-9021
CWE-77 Low
No
No
3.0.0 15.06.2018 SB2018061508