An improper input validation vulnerability in CA Privileged Access Manager 2.4.4.4 and earlier allows remote attackers to execute arbitrary commands.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| xceedium | xsuite | 2.3.0 |
| broadcom | privileged_access_manager | * |
| xceedium | xsuite | 2.4.3.0 |
Cross-site scripting (XSS) vulnerability in ajax_cmd.php in Xceedium Xsuite 2.4.4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the fileName parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| xceedium | xsuite | 2.3.0 |
| xceedium | xsuite | 2.4.3.0 |
Directory traversal vulnerability in opm/read_sessionlog.php in Xceedium Xsuite 2.4.4.5 and earlier allows remote attackers to read arbitrary files via a ....// (quadruple dot double slash) in the logFile parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| xceedium | xsuite | 2.3.0 |
| xceedium | xsuite | 2.4.3.0 |
Multiple hardcoded credentials in Xsuite 2.x.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-798,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| xceedium | xsuite | 2.3.0 |
| xceedium | xsuite | 2.4.3.0 |
Open redirect vulnerability in Xsuite 2.4.4.5 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirurl parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-601,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| xceedium | xsuite | 2.3.0 |
| xceedium | xsuite | 2.4.3.0 |
The MySQL "root" user in Xsuite 2.x does not have a password set, which allows local users to access databases on the system.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| xceedium | xsuite | 2.3.0 |
| xceedium | xsuite | 2.4.3.0 |