CVE-2018-9025: Broadcom Privileged Access Manager

High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.

An input validation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to poison log files with specially crafted input.

Affected products

  • Broadcom Privileged Access Manager: from 2.0.0, before 3.0.0 (fixed in 3.0.0)

Published 2018-06-18. Last modified 2026-06-17.