PT-2025-25755 · Fortra · Ca Privileged Access Manager

Maciej Grabiec

·

Published

2025-06-17

·

Updated

2025-06-18

·

CVE-2025-5141

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Fortra's Core Privileged Access Manager (BoKS) versions 7.2.0 through 7.2.0.17 Fortra's Core Privileged Access Manager (BoKS) versions 8.1.0 through 8.1.0.22 Fortra's Core Privileged Access Manager (BoKS) versions 8.1.1 through 8.1.1.7 Fortra's Core Privileged Access Manager (BoKS) versions 9.0.0 through 9.0.0.1 Fortra's Core Privileged Access Manager (BoKS) 7.2 without hotfix #0474 on Linux, AIX, and Solaris
Description A binary in the BoKS Server Agent component allows low privilege local users to dump data from the cache.
Recommendations For versions 7.2.0 through 7.2.0.17, apply hotfix #0474 to resolve the issue. For versions 8.1.0 through 8.1.0.22, update to a version later than 8.1.0.22. For versions 8.1.1 through 8.1.1.7, update to a version later than 8.1.1.7. For versions 9.0.0 through 9.0.0.1, update to a version later than 9.0.0.1. For BoKS 7.2 without hotfix #0474 on Linux, AIX, and Solaris, apply hotfix #0474 to resolve the issue.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-5141

Affected Products

Ca Privileged Access Manager