Skip to main content

Vendor archive

ca CVEs

Beta · best-effort

138 CVEs tagged to vendor ca48 Critical, 42 High, 45 Medium, 3 Low, 0 Unrated.

CVE-2016-9164

Published Mar 7, 2017

Directory traversal vulnerability in diag.jsp file in CA Unified Infrastructure Management (formerly CA Nimsoft Monitor) 8.4 SP1 and earlier and CA Unified Infrastructure Manageme…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9148

Published Mar 7, 2017

Cross-site scripting (XSS) vulnerability in CA Service Desk Manager (formerly CA Service Desk) 12.9 and 14.1 allows remote attackers to inject arbitrary web script or HTML via the…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9795

Published Jan 27, 2017

The casrvc program in CA Common Services, as used in CA Client Automation 12.8, 12.9, and 14.0; CA SystemEDGE 5.8.2 and 5.9; CA Systems Performance for Infrastructure Managers 12.…

CVSS 7.8 · High

CVE-2016-6152

Published Jul 26, 2016

CA eHealth 6.2.x and 6.3.x before 6.3.2.13 allows remote authenticated users to cause a denial of service or possibly execute arbitrary commands via unspecified vectors.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6151

Published Jul 26, 2016

CA eHealth 6.2.x allows remote authenticated users to cause a denial of service or possibly execute arbitrary commands via unspecified vectors.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-3318

Published Jun 17, 2015

CA Common Services, as used in CA Client Automation r12.5 SP01, r12.8, and r12.9; CA Network and Systems Management r11.0, r11.1, and r11.2; CA NSM Job Management Option r11.0, r1…

CVSS 4.6 · Medium

CVE-2015-3317

Published Jun 17, 2015

CA Common Services, as used in CA Client Automation r12.5 SP01, r12.8, and r12.9; CA Network and Systems Management r11.0, r11.1, and r11.2; CA NSM Job Management Option r11.0, r1…

CVSS 4.6 · Medium

CVE-2015-3316

Published Jun 17, 2015

CA Common Services, as used in CA Client Automation r12.5 SP01, r12.8, and r12.9; CA Network and Systems Management r11.0, r11.1, and r11.2; CA NSM Job Management Option r11.0, r1…

CVSS 4.6 · Medium

CVE-2014-8474

Published Nov 4, 2014

CA Cloud Service Management (CSM) before Summer 2014 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-8473

Published Nov 4, 2014

Cross-site request forgery (CSRF) vulnerability in CA Cloud Service Management (CSM) before Summer 2014 allows remote attackers to hijack the authentication of unspecified victims…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8472

Published Nov 4, 2014

CA Cloud Service Management (CSM) before Summer 2014 does not properly verify authentication tokens from an Identity Provider, which allows user-assisted remote attackers to bypas…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8471

Published Nov 4, 2014

CA Cloud Service Management (CSM) before Summer 2014 allows remote attackers to conduct replay attacks via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2210

Published Apr 4, 2014

Multiple directory traversal vulnerabilities in CA ERwin Web Portal 9.5 allow remote attackers to obtain sensitive information, bypass intended access restrictions, cause a denial…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-5968

Published Oct 29, 2013

Cross-site scripting (XSS) vulnerability in CA SiteMinder 12.0 through 12.51, and SiteMinder 6 Web Agents, allows remote attackers to inject arbitrary web script or HTML via vecto…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6299

Published Dec 26, 2012

Unspecified vulnerability in CA IdentityMinder r12.0 through CR16, r12.5 before SP15, and r12.6 GA allows remote attackers to bypass intended access restrictions via unknown vecto…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-6298

Published Dec 26, 2012

Unspecified vulnerability in CA IdentityMinder r12.0 through CR16, r12.5 before SP15, and r12.6 GA allows remote attackers to execute arbitrary commands or modify data via unknown…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-5973

Published Dec 10, 2012

CA XCOM Data Transport r11.0 and r11.5 on UNIX and Linux allows remote attackers to execute arbitrary commands via a crafted request.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-1446

Published Mar 21, 2012

The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Norman Anti…

CVSS 4.3 · Medium

CVE-2011-4054

Published Dec 8, 2011

Cross-site scripting (XSS) vulnerability in login.fcc in CA SiteMinder R6 SP6 before CR7 and R12 SP3 before CR8 allows remote attackers to inject arbitrary web script or HTML via…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3011

Published Aug 15, 2011

BaseServiceImpl.class in CA ARCserve D2D r15 does not properly handle sessions, which allows remote attackers to obtain credentials, and consequently execute arbitrary commands, v…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2667

Published Jul 28, 2011

Icihttp.exe in CA Gateway Security for HTTP, as used in CA Gateway Security 8.1 before 8.1.0.69 and CA Total Defense r12, does not properly parse URLs, which allows remote attacke…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 26-50 of 138 CVEsPage 2 of 6