Vulnerability Description
SSH authenticated user when access the PAM server can execute an OS command to gain the full system access using bash. This issue affects Privileged Access Manager before 3.7.0.1.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microfocus | Netiq Privileged Access Manager | < 3.7 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2020-11847?
CVE-2020-11847 is a vulnerability with a CVSS score of 8.2 (HIGH). SSH authenticated user when access the PAM server can execute an OS command to gain the full system access using bash. This issue affects Privileged Access Manager before 3.7.0.1.
How severe is CVE-2020-11847?
CVE-2020-11847 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-11847?
Check the references section above for vendor advisories and patch information. Affected products include: Microfocus Netiq Privileged Access Manager.