Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations. A malicious or compromised legacy tar-installed client selected for upgrade or patching may be able to cause commands to be executed on the BoKS Master during client version handling.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:HFortra Core Privileged Access Manager Server
APPFortra8.1.0.0 – 8.1.0.23 (bez)9.0.0.0 – 9.0.0.5 (bez)
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
Command Injection
CWE
Powiązane podatności
CVE-2026-9862CRITICAL9.8PL ✓ten sam produkt
Command injection w Fortra Core Privileged Access Manager (BoKS) — boks_autoregisterd
CVE-2025-10035CRITICAL10.0⚠ KEVPL ✓ten sam vendor
Deserialization i command injection w Fortra GoAnywhere MFT (License Servlet)
CVE-2024-6633CRITICAL9.8PL ✓ten sam vendor
Domyślne poświadczenia bazy HSQLDB w Fortra FileCatalyst Workflow
CVE-2024-5276CRITICAL9.8PL ✓ten sam vendor
SQL Injection w Fortra FileCatalyst Workflow umożliwia modyfikację danych
CVE-2024-25153CRITICAL9.8PL ✓ten sam vendor
Path traversal w Fortra FileCatalyst Workflow umożliwiający RCE przez web shell