Skip to main content

Vendor archive

ca CVEs

Beta · best-effort

138 CVEs tagged to vendor ca48 Critical, 42 High, 45 Medium, 3 Low, 0 Unrated.

CVE-2021-28250

Published Mar 26, 2021

CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a setuid (and/or setgid) file. When a component is run as an argument of the runpicEhealth…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-28249

Published Mar 26, 2021

CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a Dynamically Linked Shared Object Library. To exploit the vulnerability, the ehealth user…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-28247

Published Mar 26, 2021

CA eHealth Performance Manager through 6.3.2.12 is affected by Cross Site Scripting (XSS). The impact is: An authenticated remote user is able to inject arbitrary web script or HT…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-13821

Published Aug 30, 2018

A lack of authentication, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows remote attackers to conduct a variety of attacks, including file reading/writing.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-9027

Published Jun 18, 2018

A reflected cross-site scripting vulnerability in CA Privileged Access Manager 2.x allows remote attackers to execute malicious script with a specially crafted link.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-6589

Published May 1, 2018

CA Spectrum 10.1 prior to 10.01.02.PTF_10.1.239 and 10.2.x prior to 10.2.3 allows remote attackers to cause a denial of service via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-8954

Published Apr 11, 2018

CA Workload Control Center before r11.4 SP6 allows remote attackers to execute arbitrary code via a crafted HTTP request.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-8953

Published Apr 11, 2018

CA Workload Automation AE before r11.3.6 SP7 allows remote attackers to a perform SQL injection via a crafted HTTP request.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6588

Published Mar 29, 2018

CA API Developer Portal 3.5 up to and including 3.5 CR5 has a reflected cross-site scripting vulnerability related to the apiExplorer.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-6587

Published Mar 29, 2018

CA API Developer Portal 3.5 up to and including 3.5 CR6 has a reflected cross-site scripting vulnerability related to the widgetID variable.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-6586

Published Mar 29, 2018

CA API Developer Portal 3.5 up to and including 3.5 CR6 has a stored cross-site scripting vulnerability related to profile picture processing.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9394

Published Nov 14, 2017

A stored cross-site scripting vulnerability in CA Identity Governance 12.6 allows remote authenticated attackers to display HTML or execute script in the context of another user.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 138 CVEsPage 1 of 6