Known vulnerabilities in pam (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:pam_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 5
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.2

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting pam (Red Hat package) pam (Red Hat package) is affected by 5 known vulnerabilities: 1 medium, 4 low Critical High Medium Low

Vulnerabilities (5)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU114769 - Improper Link Resolution Before File Access ('Link Following')
CVE-2025-8941
CWE-59 Low
No
No
1.3.1-8.el8_2.2, 1.5.1-9.el9_0.3, 1.5.1-24.el9_4.1, 1.5.1-26.el9_6 03.09.2025 SB2025090350
SB2025090372
SB2025090373
and 20 more
#VU111389 - Improper Access Control
CVE-2025-6020
CWE-284 Low
No
No
1.1.8-23.el7_9.1, 1.3.1-8.el8_2.1, 1.3.1-8.el8_2.2, 1.3.1-14.el8_4.1, 1.3.1-16.el8_6.2, 1.3.1-26.el8_8.1, 1.3.1-37.el8_10, 1.5.1-9.el9_0.2, 1.5.1-9.el9_0.3, 1.5.1-15.el9_2.1, 1.5.1-24.el9_4, 1.5.1-24.el9_4.1, 1.5.1-25.el9_6, 1.5.1-26.el9_6, 1.6.1-8.el10_0 19.06.2025 SB2025061987
SB2025061992
SB20250619103
and 69 more
#VU100997 - Insecure Storage of Sensitive Information
CVE-2024-10041
CWE-922 Low
No
No
1.3.1-36.el8_10, 1.5.1-21.el9_4, 1.5.1-21.el9_5 27.11.2024 SB2024112540
SB2024112747
SB2024112748
and 38 more
#VU100912 - Improper Authentication
CVE-2024-10963
CWE-287 Medium
No
No
1.3.1-36.el8_10, 1.5.1-22.el9_5, 1.5.1-23.el9_4 25.11.2024 SB2024112540
SB2024112541
SB2024112542
and 56 more
#VU85552 - Resource exhaustion
CVE-2024-22365
CWE-400 Low
No
No
1.3.1-33.el8, 1.5.1-19.el9 17.01.2024 SB2024011799
SB20240117126
SB2024011839
and 44 more