Symantec privileged access management
This hub aggregates every CVE we track for Symantec privileged access management, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.
19
CVEs tracked
1
Critical
1
High
0
In CISA KEV
Severity distribution
HIGH1MEDIUM1CRITICAL1
Monthly trend
0
0
0
8
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Symantec privileged access management.
- CVE-2025-24507This vulnerability allows appliance compromise at boot time.
- CVE-2025-24506A specific authentication strategy allows to learn ids of PAM users associated with certain authentication types.
- CVE-2025-24505This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by uploading a specially crafted upgrade file.
- CVE-2025-24504An improper input validation the CSRF filter results in unsanitized user input written to the application logs.
- CVE-2025-24503A malicious actor can fix the session of a PAM user by tricking the user to click on a specially crafted link to the PAM server.9.6
- CVE-2025-24502An improper session validation allows an unauthenticated attacker to cause certain request notifications to be executed in the context of an incorrect user by spoofing the client IP address.
- CVE-2025-24501An improper input validation allows an unauthenticated attacker to alter PAM logs by sending a specially crafted HTTP request.
- CVE-2025-24500The vulnerability allows an unauthenticated attacker to access information in PAM database.
- CVE-2024-38496Symantec Privileged Access Manager Insecure Direct Object Reference vulnerability
- CVE-2024-38495Symantec Privileged Access Manager User Enumeration vulnerability
- CVE-2024-38494Symantec Privileged Access Manager Remote Command Execution vulnerability
- CVE-2024-38493Symantec Privileged Access Manager Reflected Cross Site Scripting vulnerability6.1
- CVE-2024-38492Symantec Privileged Access Manager Remote Command Execution vulnerability
- CVE-2024-38491Symantec Privileged Access Manager SQL Injection vulnerability
- CVE-2024-36458Symantec Privileged Access Manager Privilege Escalation vulnerability
Product normalization is registry-driven with AI assist and human review. How it works