CVE Browser

Page 1 (more results available)

Vendor: CA Remove filter Clear all
CVE-2021-28250 HIGH

CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a setuid (and/or setgid) file. When a component is run as an argument o…

CVSS 7.8 EPSS 0.34% Mar 26, 2021
CVE-2021-28249 HIGH

CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a Dynamically Linked Shared Object Library. To exploit the vulnerabilit…

CVSS 8.8 EPSS 0.41% Mar 26, 2021
CVE-2021-28247 MEDIUM

CA eHealth Performance Manager through 6.3.2.12 is affected by Cross Site Scripting (XSS). The impact is: An authenticated remote user is able to inject arbitr…

CVSS 5.4 EPSS 0.74% Mar 26, 2021
CVE-2019-13656 CRITICAL

An access vulnerability in CA Common Services DIA of CA Technologies Client Automation 14 and Workload Automation AE 11.3.5, 11.3.6 allows a remote attacker to…

CVSS 9.8 EPSS 5.82% Sep 6, 2019
CVE-2019-7393 MEDIUM

A UI redress vulnerability in the administrative user interface of CA Technologies CA Strong Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 7.1.x and CA Risk Authe…

CVSS 4.3 EPSS 2.28% May 28, 2019
CVE-2019-7394 HIGH

A privilege escalation vulnerability in the administrative user interface of CA Technologies CA Strong Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 7.1.x and CA…

CVSS 8.8 EPSS 2.82% May 28, 2019
CVE-2018-19635 CRITICAL

CA Service Desk Manager 14.1 and 17 contain a vulnerability that can allow a malicious actor to escalate privileges in the user interface.

CVSS 9.8 EPSS 1.18% Jan 22, 2019
CVE-2018-19634 HIGH

CA Service Desk Manager 14.1 and 17 contain a vulnerability that can allow a malicious actor to access survey information.

CVSS 7.5 EPSS 1.33% Jan 22, 2019
CVE-2018-14597 MEDIUM

CA Technologies Identity Governance 12.6, 14.0, 14.1, and 14.2 and CA Identity Suite Virtual Appliance 14.0, 14.1, and 14.2 provide telling error messages that…

CVSS 5.3 EPSS 1.34% Oct 17, 2018
CVE-2018-15691 CRITICAL

Insecure deserialization of a specially crafted serialized object, in CA Release Automation 6.5 and earlier, allows attackers to potentially execute arbitrary…

CVSS 9.8 EPSS 16.76% Aug 30, 2018
CVE-2018-13826 CRITICAL

An XML external entity vulnerability in the XOG functionality, in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows remote…

CVSS 9.1 EPSS 1.83% Aug 30, 2018
CVE-2018-13825 MEDIUM

Insufficient input validation in the gridExcelExport functionality, in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows re…

CVSS 6.1 EPSS 0.90% Aug 30, 2018
CVE-2018-13824 CRITICAL

Insufficient input sanitization of two parameters in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows remote attackers to…

CVSS 9.8 EPSS 1.75% Aug 30, 2018
CVE-2018-13823 HIGH

An XML external entity vulnerability in the XOG functionality, in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows remote…

CVSS 7.5 EPSS 1.88% Aug 30, 2018
CVE-2018-13822 HIGH

Unprotected storage of credentials in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows attackers to access sensitive infor…

CVSS 7.5 EPSS 1.33% Aug 30, 2018
CVE-2018-13821 CRITICAL

A lack of authentication, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows remote attackers to conduct a variety of attacks, including fil…

CVSS 9.8 EPSS 2.68% Aug 30, 2018
CVE-2018-13820 HIGH

A hardcoded passphrase, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows attackers to access sensitive information.

CVSS 7.5 EPSS 1.38% Aug 30, 2018
CVE-2018-13819 HIGH

A hardcoded secret key, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows attackers to access sensitive information.

CVSS 7.5 EPSS 1.38% Aug 30, 2018
CVE-2018-6590 MEDIUM

CA API Developer Portal 4.x, prior to v4.2.5.3 and v4.2.7.1, has an unspecified reflected cross-site scripting vulnerability.

CVSS 6.1 EPSS 0.75% Aug 3, 2018
CVE-2018-9029 CRITICAL

An improper input validation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to conduct SQL injection attacks.

CVSS 9.8 EPSS 1.73% Jun 18, 2018
CVE-2018-9028 HIGH

Weak cryptography used for passwords in CA Privileged Access Manager 2.x reduces the complexity for password cracking.

CVSS 7.5 EPSS 0.90% Jun 18, 2018
CVE-2018-9027 MEDIUM

A reflected cross-site scripting vulnerability in CA Privileged Access Manager 2.x allows remote attackers to execute malicious script with a specially crafted…

CVSS 6.1 EPSS 0.90% Jun 18, 2018
CVE-2018-9026 HIGH

A session fixation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to hijack user sessions with a specially crafted request.

CVSS 7.5 EPSS 1.32% Jun 18, 2018
CVE-2018-9025 HIGH

An input validation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to poison log files with specially crafted input.

CVSS 7.5 EPSS 1.39% Jun 18, 2018
CVE-2018-9024 MEDIUM

An improper authentication vulnerability in CA Privileged Access Manager 2.x allows attackers to spoof IP addresses in a log file.

CVSS 5.3 EPSS 1.13% Jun 18, 2018

Showing 1 to 25 CVEs · page 1 (more available)