VYPR
Vendor

Ca Technologies, A Broadcom Company

Products
26
CVEs
17
Across products
27
Status
Private

Products

26

Recent CVEs

17
  • CVE-2019-19230CriDec 9, 2019
    risk 0.64cvss 9.8epss 0.04

    An unsafe deserialization vulnerability exists in CA Release Automation (Nolio) 6.6 with the DataManagement component that can allow a remote attacker to execute arbitrary code.

  • CVE-2019-13658CriOct 2, 2019
    risk 0.64cvss 9.8epss 0.03

    CA Network Flow Analysis 9.x and 10.0.x have a default credential vulnerability that can allow a remote attacker to execute arbitrary commands and compromise system security.

  • CVE-2019-13656CriSep 6, 2019
    risk 0.64cvss 9.8epss 0.06

    An access vulnerability in CA Common Services DIA of CA Technologies Client Automation 14 and Workload Automation AE 11.3.5, 11.3.6 allows a remote attacker to execute arbitrary code.

  • CVE-2019-7394HigMay 28, 2019
    risk 0.57cvss 8.8epss 0.03

    A privilege escalation vulnerability in the administrative user interface of CA Technologies CA Strong Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 7.1.x and CA Risk Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 3.1.x allows an authenticated attacker to gain additional privileges in…

  • CVE-2016-5803HigFeb 13, 2017
    risk 0.56cvss 8.6epss 0.02

    An issue was discovered in CA Unified Infrastructure Management Version 8.47 and earlier. The Unified Infrastructure Management software uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such…

  • CVE-2020-29478HigJan 5, 2021
    risk 0.49cvss 7.5epss 0.01

    CA Service Catalog 17.2 and 17.3 contain a vulnerability in the default configuration of the Setup Utility that may allow a remote attacker to cause a denial of service condition.

  • CVE-2018-14597MedOct 17, 2018
    risk 0.35cvss 5.3epss 0.01

    CA Technologies Identity Governance 12.6, 14.0, 14.1, and 14.2 and CA Identity Suite Virtual Appliance 14.0, 14.1, and 14.2 provide telling error messages that may allow remote attackers to enumerate account names.

  • CVE-2019-7393MedMay 28, 2019
    risk 0.28cvss 4.3epss 0.02

    A UI redress vulnerability in the administrative user interface of CA Technologies CA Strong Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 7.1.x and CA Risk Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 3.1.x may allow a remote attacker to gain sensitive information in some cases.

  • CVE-2015-3317Jun 17, 2015
    risk 0.00cvss epss 0.00

    CA Common Services, as used in CA Client Automation r12.5 SP01, r12.8, and r12.9; CA Network and Systems Management r11.0, r11.1, and r11.2; CA NSM Job Management Option r11.0, r11.1, and r11.2; CA Universal Job Management Agent; CA Virtual Assurance for Infrastructure Managers…

  • CVE-2015-2827Apr 8, 2015
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in CA Spectrum 9.2.x and 9.3.x before 9.3 H02 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2014-8472Nov 4, 2014
    risk 0.00cvss epss 0.02

    CA Cloud Service Management (CSM) before Summer 2014 does not properly verify authentication tokens from an Identity Provider, which allows user-assisted remote attackers to bypass intended access restrictions via unspecified vectors.

  • CVE-2013-2279Mar 21, 2013
    risk 0.00cvss epss 0.02

    CA SiteMinder Federation (FSS) 12.5, 12.0, and r6; Federation (Standalone) 12.1 and 12.0; Agent for SharePoint 2010; and SiteMinder for Secure Proxy Server 6.0, 12.0, and 12.5 does not properly verify XML signatures for SAML statements, which allows remote attackers to spoof…

  • CVE-2012-2971Oct 20, 2012
    risk 0.00cvss epss 0.04

    The server in CA ARCserve Backup r12.5, r15, and r16 on Windows does not properly process RPC requests, which allows remote attackers to execute arbitrary code or cause a denial of service via a crafted request.

  • CVE-2012-0692Oct 2, 2012
    risk 0.00cvss epss 0.00

    CA License (aka CA Licensing) before 1.90.03 allows local users to modify or create arbitrary files, and consequently gain privileges, via unspecified vectors.

  • CVE-2011-4054Dec 8, 2011
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in login.fcc in CA SiteMinder R6 SP6 before CR7 and R12 SP3 before CR8 allows remote attackers to inject arbitrary web script or HTML via the postpreservationdata parameter.

  • CVE-2011-1036Feb 25, 2011
    risk 0.00cvss epss 0.03

    The XML Security Database Parser class in the XMLSecDB ActiveX control in the HIPSEngine component in the Management Server before 8.1.0.88, and the client before 1.6.450, in CA Host-Based Intrusion Prevention System (HIPS) 8.1, as used in CA Internet Security Suite (ISS) 2010,…

  • CVE-2010-2157Jun 7, 2010
    risk 0.00cvss epss 0.00

    Unspecified vulnerability in CA ARCserve Backup r11.5 SP4, r12.0 SP2, and r12.5 SP1 on Windows allows local users to obtain sensitive information via unknown vectors.