CyberRota Analysis
AI-GeneratedFortra BoKS Manager is vulnerable to a critical command injection flaw in the crlserver component, allowing authenticated users with permissions to add CRL URLs to execute arbitrary shell commands as root. This vulnerability poses a significant risk as it can be exploited through network-accessible administration interfaces without requiring elevated local privileges. Organizations using Fortra BoKS Manager should prioritize immediate remediation to mitigate potential unauthorized access and system compromise.
Original NVD Description
Fortra BoKS Manager contains a command injection vulnerability in crlserver. An authenticated user authorized to add CRL URLs through BCC, the WSI REST or SOAP API, or the cacrl command-line interface could cause shell command substitution to be processed by crlserver as root on the BoKS Master. BCC and WSI provide network-accessible administration paths and do not require a local sudo or suexec rule; non-root use of cacrl requires such a rule.