PT-2021-17835 · Ca · Ca Ehealth Performance Manager

Published

2021-03-26

·

Updated

2024-08-03

·

CVE-2021-28250

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: CA eHealth Performance Manager versions 6.3.2.12 and earlier
Description: The issue is related to Privilege Escalation via a setuid (and/or setgid) file. When a component is run as an argument of the runpicEhealth executable, the script code will be executed as the ehealth user. This issue only affects products that are no longer supported by the maintainer.
Recommendations: For CA eHealth Performance Manager versions 6.3.2.12 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2021-28250

Affected Products

Ca Ehealth Performance Manager