CVE-2019-7392

Severity
9.1CRITICAL
EPSS
0.4%
top 36.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 26
Latest updateMay 13

Description

An improper authentication vulnerability in CA Privileged Access Manager 3.x Web-UI jk-manager and jk-status allows a remote attacker to gain sensitive information or alter configuration.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 3.9 | Impact: 5.2

Affected Packages1 packages

NVDbroadcom/privileged_access_manager3.0.13.0.3+2

🔴Vulnerability Details

2
GHSA
GHSA-w7h6-3jpg-mpq7: An improper authentication vulnerability in CA Privileged Access Manager 32022-05-13
CVEList
CVE-2019-7392: An improper authentication vulnerability in CA Privileged Access Manager 32019-02-26
CVE-2019-7392 (CRITICAL CVSS 9.1) | An improper authentication vulnerab | cvebase.io