Lucene search

K
cvelistMitreCVELIST:CVE-2021-28249
HistoryMar 26, 2021 - 7:11 a.m.

CVE-2021-28249

2021-03-2607:11:42
mitre
www.cve.org
3
ehealth
privilege escalation
dynamically linked shared object library

AI Score

8.8

Confidence

High

EPSS

0.001

Percentile

20.7%

CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a Dynamically Linked Shared Object Library. To exploit the vulnerability, the ehealth user must create a malicious library in the writable RPATH, to be dynamically linked when the FtpCollector executable is run. The code in the library will be executed as the root user. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

AI Score

8.8

Confidence

High

EPSS

0.001

Percentile

20.7%

Related for CVELIST:CVE-2021-28249