#VU13356 Open redirect in Privileged Access Manager


Published: 2020-03-18

Vulnerability identifier: #VU13356

Vulnerability risk: Low

CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N/E:P/RL:O/RC:C]

CVE-ID: CVE-2015-4668

CWE-ID: CWE-601

Exploitation vector: Network

Exploit availability: Yes

Vulnerable software:
Privileged Access Manager
Web applications / Remote management & hosting panels

Vendor: CA Technologies

Description
The vulnerability allows a remote unauthenticated attacker to redirect the target user to external websites.

The weakness exists due to open redirect in openwin.php script. A remote attacker can use a specially crafted image link, trick the victim into opening it and redirect users to malicious website.

Mitigation
Update to version 3.0.0 or later.

Vulnerable software versions

Privileged Access Manager: All versions


External links
http://seclists.org/bugtraq/2018/Jun/46


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.


Latest bulletins with this vulnerability