Medium severity6.1NVD Advisory· Published Feb 6, 2019· Updated Jun 17, 2026
CVE-2019-6504
CVE-2019-6504
Description
Insufficient output sanitization in the Automic Web Interface (AWI), in CA Automic Workload Automation 12.0 to 12.2, allow attackers to potentially conduct persistent cross site scripting (XSS) attacks via a crafted object.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:broadcom:automic_workload_automation:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:broadcom:automic_workload_automation:*:*:*:*:*:*:*:*range: >=12.0,<=12.2
- (no CPE)range: 12.0 to 12.2
- Range: 12.0 to 12.2
- CA Technologies - A Broadcom Company/CA Automic Workload Automationv5Range: CA Automic Workload Automation 12.0 prior to Automic.Web.Interface 12.0.6 HF2 CA Automic Workload Automation 12.1 prior to Automic.Web.Interface 12.1.3 HF3 CA Automic Workload Automation 12.2 prior to Automic.Web.Interface 12.2.1 HF1
Patches
Vulnerability mechanics
References
7- www.securityfocus.com/bid/106755nvdThird Party AdvisoryVDB Entry
- communities.ca.com/community/product-vulnerability-response/blog/2019/01/24/ca20190124-01-security-notice-for-ca-automic-workload-automationnvdVendor Advisory
- marc.infonvdMailing ListThird Party Advisory
- packetstormsecurity.com/files/151325/CA-Automic-Workload-Automation-12.x-Cross-Site-Scripting.htmlnvdThird Party AdvisoryVDB Entry
- sec-consult.com/en/blog/advisories/cross-site-scripting-in-ca-automic-workload-automation-web-interface-formerly-automic-automation-engine/nvdThird Party Advisory
- seclists.org/fulldisclosure/2019/Jan/61nvdMailing ListThird Party Advisory
- support.ca.com/us/product-content/recommended-reading/security-notices/CA20190124-01-security-notice-for-ca-automic-workload-automation.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.