Loading HuntDB...

Vulnerabilities

CVE-2019-13656

CRITICAL

An access vulnerability in CA Common Services DIA of CA Technologies Client Automation 14 and Workload Automation AE 11.3.5, 11.3.6 allows a remote attacker to execute arbitrary code.

Published Sep 06, 2019

CVE-2018-19635

UNKNOWN

CA Service Desk Manager 14.1 and 17 contain a vulnerability that can allow a malicious actor to escalate privileges in the user interface.

Published Jan 22, 2019

CVE-2018-19634

UNKNOWN

CA Service Desk Manager 14.1 and 17 contain a vulnerability that can allow a malicious actor to access survey information.

Published Jan 22, 2019

CVE-2018-14597

UNKNOWN

CA Technologies Identity Governance 12.6, 14.0, 14.1, and 14.2 and CA Identity Suite Virtual Appliance 14.0, 14.1, and 14.2 provide telling error messages that may allow remote attackers to enumerate account names.

Published Oct 17, 2018

CVE-2018-13819

UNKNOWN

A hardcoded secret key, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows attackers to access sensitive information.

Published Aug 30, 2018

CVE-2018-13820

UNKNOWN

A hardcoded passphrase, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows attackers to access sensitive information.

Published Aug 30, 2018

CVE-2018-13824

UNKNOWN

Insufficient input sanitization of two parameters in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows remote attackers to execute SQL injection attacks.

Published Aug 30, 2018

CVE-2018-15691

UNKNOWN

Insecure deserialization of a specially crafted serialized object, in CA Release Automation 6.5 and earlier, allows attackers to potentially execute arbitrary code.

Published Aug 30, 2018

CVE-2018-13825

UNKNOWN

Insufficient input validation in the gridExcelExport functionality, in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows remote attackers to execute reflected cross-site scripting attacks.

Published Aug 30, 2018

CVE-2018-13822

UNKNOWN

Unprotected storage of credentials in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows attackers to access sensitive information.

Published Aug 30, 2018

CVE-2018-13823

UNKNOWN

An XML external entity vulnerability in the XOG functionality, in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows remote attackers to access sensitive information.

Published Aug 30, 2018

CVE-2018-13826

UNKNOWN

An XML external entity vulnerability in the XOG functionality, in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows remote attackers to conduct server side request forgery attacks.

Published Aug 30, 2018

CVE-2018-13821

UNKNOWN

A lack of authentication, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows remote attackers to conduct a variety of attacks, including file reading/writing.

Published Aug 30, 2018

CVE-2018-6590

UNKNOWN

CA API Developer Portal 4.x, prior to v4.2.5.3 and v4.2.7.1, has an unspecified reflected cross-site scripting vulnerability.

Published Aug 03, 2018

CVE-2015-4664

UNKNOWN

An improper input validation vulnerability in CA Privileged Access Manager 2.4.4.4 and earlier allows remote attackers to execute arbitrary commands.

Published Jun 18, 2018

CVE-2018-9023

UNKNOWN

An input validation vulnerability in CA Privileged Access Manager 2.x allows unprivileged users to execute arbitrary commands by passing specially crafted arguments to the update_crld script.

Published Jun 18, 2018

CVE-2018-9021

UNKNOWN

An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary commands with specially crafted requests.

Published Jun 18, 2018

CVE-2018-9028

UNKNOWN

Weak cryptography used for passwords in CA Privileged Access Manager 2.x reduces the complexity for password cracking.

Published Jun 18, 2018

CVE-2018-9029

UNKNOWN

An improper input validation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to conduct SQL injection attacks.

Published Jun 18, 2018

CVE-2018-9027

UNKNOWN

A reflected cross-site scripting vulnerability in CA Privileged Access Manager 2.x allows remote attackers to execute malicious script with a specially crafted link.

Published Jun 18, 2018

CVE-2018-9025

UNKNOWN

An input validation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to poison log files with specially crafted input.

Published Jun 18, 2018

CVE-2018-9024

UNKNOWN

An improper authentication vulnerability in CA Privileged Access Manager 2.x allows attackers to spoof IP addresses in a log file.

Published Jun 18, 2018

CVE-2018-9022

UNKNOWN

An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary code or commands by poisoning a configuration file.

Published Jun 18, 2018

CVE-2018-9026

UNKNOWN

A session fixation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to hijack user sessions with a specially crafted request.

Published Jun 18, 2018

CVE-2018-6589

UNKNOWN

CA Spectrum 10.1 prior to 10.01.02.PTF_10.1.239 and 10.2.x prior to 10.2.3 allows remote attackers to cause a denial of service via unspecified vectors.

Published May 01, 2018

CVE-2018-8953

UNKNOWN

CA Workload Automation AE before r11.3.6 SP7 allows remote attackers to a perform SQL injection via a crafted HTTP request.

Published Apr 11, 2018

CVE-2018-8954

UNKNOWN

CA Workload Control Center before r11.4 SP6 allows remote attackers to execute arbitrary code via a crafted HTTP request.

Published Apr 11, 2018

CVE-2018-6586

UNKNOWN

CA API Developer Portal 3.5 up to and including 3.5 CR6 has a stored cross-site scripting vulnerability related to profile picture processing.

Published Mar 29, 2018

CVE-2018-6587

UNKNOWN

CA API Developer Portal 3.5 up to and including 3.5 CR6 has a reflected cross-site scripting vulnerability related to the widgetID variable.

Published Mar 29, 2018

CVE-2018-6588

UNKNOWN

CA API Developer Portal 3.5 up to and including 3.5 CR5 has a reflected cross-site scripting vulnerability related to the apiExplorer.

Published Mar 29, 2018

CVE-2017-9394

UNKNOWN

A stored cross-site scripting vulnerability in CA Identity Governance 12.6 allows remote authenticated attackers to display HTML or execute script in the context of another user.

Published Nov 14, 2017

CVE-2017-9393

UNKNOWN

CA Identity Manager r12.6 to r12.6 SP8, 14.0, and 14.1 allows remote attackers to potentially identify passwords of locked accounts through an exhaustive search.

Published Sep 22, 2017