CVE-2021-28250

CVE-2021-28250 – CA eHealth Performance Manager

Vulnerability Description: Privilege Escalation via SUID/GUID file - CWE-250
Software Version: CA eHealth Performance Manager <= 6.3.2.12
NISThttps://nvd.nist.gov/vuln/detail/CVE-2021-28250
CVSv3: 7.8
Severity: High
Credits
: Veno Eivazian, Alessandro Sabetta, Massimiliano Brolli

CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a setuid (and/or setgid) file. When a component is run as an argument of the runpicEhealth executable, the script code will be executed as the ehealth user.