VYPR
Unrated severityNVD Advisory· Published Mar 13, 2024· Updated Aug 26, 2024

Insecure renegotiation in SSL protocol caused Denial of service attack in Privileged Account Manager

CVE-2020-11862

Description

Allocation of Resources Without Limits or Throttling vulnerability in OpenText NetIQ Privileged Account Manager on Linux, Windows, 64 bit allows Flooding.This issue affects NetIQ Privileged Account Manager: before 3.7.0.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

NetIQ Privileged Account Manager before 3.7.0.2 suffers from an unthrottled resource allocation flaw that can be exploited for denial of service.

Vulnerability

CVE-2020-11862 is an Allocation of Resources Without Limits or Throttling vulnerability in OpenText NetIQ Privileged Account Manager (PAM). The issue affects all versions of NetIQ PAM before 3.7.0.2, on Linux, Windows, and 64-bit platforms. The vulnerability resides in a component where resource allocation lacks appropriate limits or throttling, allowing an attacker to exhaust system resources by triggering uncontrolled resource consumption.

Exploitation

An attacker does not require authentication to exploit this vulnerability; they can send specially crafted requests from a network position that is reachable to the affected PAM service. While no detailed exploit sequence is provided in references, the vulnerability class (flooding) indicates that repeated or sustained requests can cause the system to allocate resources without bound, leading to exhaustion.

Impact

Successful exploitation leads to a denial of service (DoS) condition. The attacker can cause the service to become unresponsive due to resource exhaustion, affecting availability. There is no indication of data confidentiality or integrity compromise; the primary impact is on system availability.

Mitigation

The vulnerability is fixed in version NetIQ Privileged Account Manager 3.7.0.2 (3.7 Patch Update 2), released in September 2020 per the release notes [1]. Users should upgrade to version 3.7.0.2 or later. No workarounds are documented in available references. If upgrade is not immediately possible, organizations may consider network-level restrictions to limit exposure to potentially malicious traffic.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.