CVE-2015-4664
Published Jun 18, 2018An improper input validation vulnerability in CA Privileged Access Manager 2.4.4.4 and earlier allows remote attackers to execute arbitrary commands.
Vendor/product archive
6 CVEs tagged to xceedium / xsuite — 2 Critical, 1 High, 3 Medium, 0 Low, 0 Unrated.
An improper input validation vulnerability in CA Privileged Access Manager 2.4.4.4 and earlier allows remote attackers to execute arbitrary commands.
The MySQL "root" user in Xsuite 2.x does not have a password set, which allows local users to access databases on the system.
Open redirect vulnerability in Xsuite 2.4.4.5 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirurl p…
Multiple hardcoded credentials in Xsuite 2.x.
Directory traversal vulnerability in opm/read_sessionlog.php in Xceedium Xsuite 2.4.4.5 and earlier allows remote attackers to read arbitrary files via a ....// (quadruple dot dou…
Cross-site scripting (XSS) vulnerability in ajax_cmd.php in Xceedium Xsuite 2.4.4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the fileName par…