VYPR

Vendor CVEs

Ca

All CVEs

274 total · sorted by risk
  • CVE-2020-8012CriFeb 18, 2020
    risk 0.73cvss 9.8epss 0.77

    CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a buffer overflow vulnerability in the robot (controller) component. A remote attacker can execute arbitrary code.

  • CVE-2020-8010CriFeb 18, 2020
    risk 0.71cvss 9.8epss 0.49

    CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains an improper ACL handling vulnerability in the robot (controller) component. A remote attacker can execute commands, read from, or write to the target system.

  • CVE-2018-15691CriAug 30, 2018
    risk 0.68cvss 9.8epss 0.17

    Insecure deserialization of a specially crafted serialized object, in CA Release Automation 6.5 and earlier, allows attackers to potentially execute arbitrary code.

  • CVE-2018-9021CriJun 18, 2018
    risk 0.68cvss 9.8epss 0.19

    An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary commands with specially crafted requests.

  • CVE-2015-4664CriJun 18, 2018
    risk 0.68cvss 9.8epss 0.21

    An improper input validation vulnerability in CA Privileged Access Manager 2.4.4.4 and earlier allows remote attackers to execute arbitrary commands.

  • CVE-2020-11658CriApr 15, 2020
    risk 0.64cvss 9.8epss 0.02

    CA API Developer Portal 4.3.1 and earlier handles shared secret keys in an insecure manner, which allows attackers to bypass authorization.

  • CVE-2019-19230CriDec 9, 2019
    risk 0.64cvss 9.8epss 0.04

    An unsafe deserialization vulnerability exists in CA Release Automation (Nolio) 6.6 with the DataManagement component that can allow a remote attacker to execute arbitrary code.

  • CVE-2019-13657CriOct 17, 2019
    risk 0.64cvss 9.8epss 0.03

    CA Performance Management 3.5.x, 3.6.x before 3.6.9, and 3.7.x before 3.7.4 have a default credential vulnerability that can allow a remote attacker to execute arbitrary commands and compromise system security.

  • CVE-2019-13658CriOct 2, 2019
    risk 0.64cvss 9.8epss 0.03

    CA Network Flow Analysis 9.x and 10.0.x have a default credential vulnerability that can allow a remote attacker to execute arbitrary commands and compromise system security.

  • CVE-2018-19635CriJan 22, 2019
    risk 0.64cvss 9.8epss 0.01

    CA Service Desk Manager 14.1 and 17 contain a vulnerability that can allow a malicious actor to escalate privileges in the user interface.

  • CVE-2018-13824CriAug 30, 2018
    risk 0.64cvss 9.8epss 0.02

    Insufficient input sanitization of two parameters in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows remote attackers to execute SQL injection attacks.

  • CVE-2018-13821CriAug 30, 2018
    risk 0.64cvss 9.8epss 0.03

    A lack of authentication, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows remote attackers to conduct a variety of attacks, including file reading/writing.

  • CVE-2018-8954CriApr 11, 2018
    risk 0.64cvss 9.8epss 0.07

    CA Workload Control Center before r11.4 SP6 allows remote attackers to execute arbitrary code via a crafted HTTP request.

  • CVE-2017-9393CriSep 22, 2017
    risk 0.64cvss 9.8epss 0.02

    CA Identity Manager r12.6 to r12.6 SP8, 14.0, and 14.1 allows remote attackers to potentially identify passwords of locked accounts through an exhaustive search.

  • CVE-2019-7392CriFeb 26, 2019
    risk 0.59cvss 9.1epss 0.02

    An improper authentication vulnerability in CA Privileged Access Manager 3.x Web-UI jk-manager and jk-status allows a remote attacker to gain sensitive information or alter configuration.

  • CVE-2018-13826CriAug 30, 2018
    risk 0.59cvss 9.1epss 0.02

    An XML external entity vulnerability in the XOG functionality, in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows remote attackers to conduct server side request forgery attacks.

  • CVE-2015-6854CriMar 24, 2016
    risk 0.59cvss 9.1epss 0.01

    The non-Domino web agents in CA Single Sign-On (aka SSO, formerly SiteMinder) R6, R12.0 before SP3 CR13, R12.0J before SP3 CR1.2, and R12.5 before CR5 allow remote attackers to cause a denial of service (daemon crash) or obtain sensitive information via a crafted request.

  • CVE-2015-6853CriMar 24, 2016
    risk 0.59cvss 9.1epss 0.01

    The Domino web agent in CA Single Sign-On (aka SSO, formerly SiteMinder) R6, R12.0 before SP3 CR13, R12.0J before SP3 CR1.2, R12.5 before CR5, R12.51 before CR4, and R12.52 before SP1 CR3 allows remote attackers to cause a denial of service (daemon crash) or obtain sensitive…

  • CVE-2024-38499HigDec 17, 2024
    risk 0.57cvss 8.8epss 0.00

    CA Client Automation (ITCM) allows non-admin/non-root users to encrypt a string using CAF CLI and SD_ACMD CLI. This would allow the non admin user to access the critical encryption keys which further causes the exploitation of stored credentials. This fix doesn't allow a…

  • CVE-2022-22689HigFeb 4, 2022
    risk 0.57cvss 8.8epss 0.01

    CA Harvest Software Change Manager versions 13.0.3, 13.0.4, 14.0.0, and 14.0.1, contain a vulnerability in the CSV export functionality, due to insufficient input validation, that can allow a privileged user to potentially execute arbitrary code or commands.

  • CVE-2021-28249HigMar 26, 2021
    risk 0.57cvss 8.8epss 0.00

    CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a Dynamically Linked Shared Object Library. To exploit the vulnerability, the ehealth user must create a malicious library in the writable RPATH, to be dynamically linked when the…

  • CVE-2020-11666HigApr 15, 2020
    risk 0.57cvss 8.8epss 0.03

    CA API Developer Portal 4.3.1 and earlier contains an access control flaw that allows malicious users to elevate privileges.

  • CVE-2019-7394HigMay 28, 2019
    risk 0.57cvss 8.8epss 0.03

    A privilege escalation vulnerability in the administrative user interface of CA Technologies CA Strong Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 7.1.x and CA Risk Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 3.1.x allows an authenticated attacker to gain additional privileges in…

  • CVE-2018-8953HigApr 11, 2018
    risk 0.57cvss 8.8epss 0.03

    CA Workload Automation AE before r11.3.6 SP7 allows remote attackers to a perform SQL injection via a crafted HTTP request.

  • CVE-2016-6152HigJul 26, 2016
    risk 0.57cvss 8.8epss 0.03

    CA eHealth 6.2.x and 6.3.x before 6.3.2.13 allows remote authenticated users to cause a denial of service or possibly execute arbitrary commands via unspecified vectors.

  • CVE-2016-6151HigJul 26, 2016
    risk 0.57cvss 8.8epss 0.03

    CA eHealth 6.2.x allows remote authenticated users to cause a denial of service or possibly execute arbitrary commands via unspecified vectors.

  • CVE-2016-5803HigFeb 13, 2017
    risk 0.56cvss 8.6epss 0.02

    An issue was discovered in CA Unified Infrastructure Management Version 8.47 and earlier. The Unified Infrastructure Management software uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such…

  • CVE-2020-27858HigJan 20, 2021
    risk 0.55cvss 7.5epss 0.74

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of CA Arcserve D2D 16.5. Authentication is not required to exploit this vulnerability. The specific flaw exists within the getNews method. Due to the improper restriction of…

  • CVE-2020-11661HigApr 15, 2020
    risk 0.53cvss 8.1epss 0.02

    CA API Developer Portal 4.3.1 and earlier contains an access control flaw that allows privileged users to view and edit user data.

  • CVE-2016-10086HigJan 18, 2017
    risk 0.53cvss 8.1epss 0.02

    RESTful web services in CA Service Desk Manager 12.9 and CA Service Desk Management 14.1 might allow remote authenticated users to read or modify task information by leveraging incorrect permissions applied to a RESTful request.

  • CVE-2021-28250HigMar 26, 2021
    risk 0.51cvss 7.8epss 0.00

    CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a setuid (and/or setgid) file. When a component is run as an argument of the runpicEhealth executable, the script code will be executed as the ehealth user. NOTE: This vulnerability only…

  • CVE-2021-28246HigMar 26, 2021
    risk 0.51cvss 7.8epss 0.00

    CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a Dynamically Linked Shared Object Library. A regular user must create a malicious library in the writable RPATH, to be dynamically linked when the emtgtctl2 executable is run. The code in…

  • CVE-2020-28421HigNov 23, 2020
    risk 0.51cvss 7.8epss 0.00

    CA Unified Infrastructure Management 20.1 and earlier contains a vulnerability in the robot (controller) component that allows local attackers to elevate privileges.

  • CVE-2019-19544HigJan 8, 2020
    risk 0.51cvss 7.8epss 0.00

    CA Automic Dollar Universe 5.3.3 contains a vulnerability, related to the uxdqmsrv binary being setuid root, that allows local attackers to elevate privileges. This vulnerability was reported to CA several years after CA Automic Dollar Universe 5.3.3 reached End of Life (EOL)…

  • CVE-2016-9795HigJan 27, 2017
    risk 0.51cvss 7.8epss 0.01

    The casrvc program in CA Common Services, as used in CA Client Automation 12.8, 12.9, and 14.0; CA SystemEDGE 5.8.2 and 5.9; CA Systems Performance for Infrastructure Managers 12.8 and 12.9; CA Universal Job Management Agent 11.2; CA Virtual Assurance for Infrastructure Managers…

  • CVE-2022-33756HigJun 16, 2022
    risk 0.49cvss 7.5epss 0.01

    CA Automic Automation 12.2 and 12.3 contain an entropy weakness vulnerability in the Automic AutomationEngine that could allow a remote attacker to potentially access sensitive data.

  • CVE-2021-28248HigMar 26, 2021
    risk 0.49cvss 7.5epss 0.01

    CA eHealth Performance Manager through 6.3.2.12 is affected by Improper Restriction of Excessive Authentication Attempts. An attacker is able to perform an arbitrary number of /web/frames/ authentication attempts using different passwords, and eventually gain access to a…

  • CVE-2020-29478HigJan 5, 2021
    risk 0.49cvss 7.5epss 0.01

    CA Service Catalog 17.2 and 17.3 contain a vulnerability in the default configuration of the Setup Utility that may allow a remote attacker to cause a denial of service condition.

  • CVE-2020-11662HigApr 15, 2020
    risk 0.49cvss 7.5epss 0.03

    CA API Developer Portal 4.3.1 and earlier handles requests insecurely, which allows remote attackers to exploit a Cross-Origin Resource Sharing flaw and access sensitive information.

  • CVE-2020-8011HigFeb 18, 2020
    risk 0.49cvss 7.5epss 0.02

    CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a null pointer dereference vulnerability in the robot (controller) component. A remote attacker can crash the Controller service.

  • CVE-2018-19634HigJan 22, 2019
    risk 0.49cvss 7.5epss 0.01

    CA Service Desk Manager 14.1 and 17 contain a vulnerability that can allow a malicious actor to access survey information.

  • CVE-2018-13823HigAug 30, 2018
    risk 0.49cvss 7.5epss 0.02

    An XML external entity vulnerability in the XOG functionality, in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows remote attackers to access sensitive information.

  • CVE-2018-13822HigAug 30, 2018
    risk 0.49cvss 7.5epss 0.01

    Unprotected storage of credentials in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows attackers to access sensitive information.

  • CVE-2018-13820HigAug 30, 2018
    risk 0.49cvss 7.5epss 0.01

    A hardcoded passphrase, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows attackers to access sensitive information.

  • CVE-2018-13819HigAug 30, 2018
    risk 0.49cvss 7.5epss 0.01

    A hardcoded secret key, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows attackers to access sensitive information.

  • CVE-2018-6589HigMay 1, 2018
    risk 0.49cvss 7.5epss 0.02

    CA Spectrum 10.1 prior to 10.01.02.PTF_10.1.239 and 10.2.x prior to 10.2.3 allows remote attackers to cause a denial of service via unspecified vectors.

  • CVE-2016-9165HigMar 20, 2017
    risk 0.49cvss 7.5epss 0.04

    The get_sessions servlet in CA Unified Infrastructure Management (formerly CA Nimsoft Monitor) before 8.5 and CA Unified Infrastructure Management Snap (formerly CA Nimsoft Monitor Snap) allows remote attackers to obtain active session ids and consequently bypass authentication…

  • CVE-2016-9164HigMar 7, 2017
    risk 0.49cvss 7.5epss 0.05

    Directory traversal vulnerability in diag.jsp file in CA Unified Infrastructure Management (formerly CA Nimsoft Monitor) 8.4 SP1 and earlier and CA Unified Infrastructure Management Snap (formerly CA Nimsoft Monitor Snap) allows remote attackers to read arbitrary files via…

  • CVE-2015-8698HigJun 29, 2016
    risk 0.46cvss 7.1epss 0.01

    CA Release Automation (formerly LISA Release Automation) 5.0.2 before 5.0.2-227, 5.5.1 before 5.5.1-1616, 5.5.2 before 5.5.2-434, and 6.1.0 before 6.1.0-1026 allows remote attackers to read arbitrary files or cause a denial of service via a request containing an XML external…

  • CVE-2021-44050MedDec 2, 2021
    risk 0.42cvss 6.5epss 0.01

    CA Network Flow Analysis (NFA) 21.2.1 and earlier contain a SQL injection vulnerability in the NFA web application, due to insufficient input validation, that could potentially allow an authenticated user to access sensitive data.

Page 1 of 6