CVE-2020-11847: Micro Focus Netiq Privileged Access Manager

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

SSH authenticated user when access the PAM server can execute an OS command to gain the full system access using bash. This issue affects Privileged Access Manager before 3.7.0.1.

Affected products

  • Micro Focus Netiq Privileged Access Manager: before 3.7 (fixed in 3.7); version 3.7 only

Published 2024-08-21. Last modified 2026-06-17.