CVE-2020-11847

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
21/08/2024
Last modified:
23/08/2024

Description

SSH authenticated user when access the PAM server can execute an OS command to gain the full system access using bash. This issue affects Privileged Access Manager before 3.7.0.1.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:microfocus:netiq_privileged_access_manager:*:*:*:*:*:*:*:* 3.7 (excluding)
cpe:2.3:a:microfocus:netiq_privileged_access_manager:3.7:-:*:*:*:*:*:*