PT-2019-18576 · Ca · Ca Privileged Access Manager
Bob Brust
·
Published
2019-02-26
·
Updated
2021-04-12
·
CVE-2019-7392
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
CA Privileged Access Manager versions 3.x
Description
The issue is related to an improper authentication mechanism in the Web-UI jk-manager and jk-status components, allowing a remote attacker to obtain sensitive information or modify the configuration.
Recommendations
For CA Privileged Access Manager versions 3.x, consider restricting access to the jk-manager and jk-status components until a proper fix is applied. As a temporary workaround, review and strengthen authentication mechanisms to minimize the risk of exploitation.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ca Privileged Access Manager