Vulnerability index

Browse CVEs

479 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fabric Operating System MEDIUM 6.1
CVE-2018-6449

Host Header Injection vulnerability in the http management interface in Brocade Fabric OS versions before v9.0.0 could allow a remote attacker to exp…

Fix: 9.0.0+
Fix from $1,600 2020-09-25
Fabric Operating System MEDIUM 5.5
CVE-2020-15372

A vulnerability in the command-line interface in Brocade Fabric OS before Brocade Fabric OS v8.2.2a1, 8.2.2c, v7.4.2g, v8.2.0_CBN3, v8.2.1e, v8.1.2k,…

Fix: 7.4.2g / 8.1.2k+
Fix from $1,600 2020-09-25
Fabric Operating System MEDIUM 5.4
CVE-2018-6447

A Reflective XSS Vulnerability in HTTP Management Interface in Brocade Fabric OS versions before Brocade Fabric OS v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k,…

Mitigation only
Fix from $1,600 2020-09-25
Rabbitmq Server MEDIUM 6.7
CVE-2020-5419

RabbitMQ versions 3.8.x prior to 3.8.7 are prone to a Windows-specific binary planting security vulnerability that allows for arbitrary code executio…

Fix: 3.7.28 / 3.8.7+
Fix from $1,600 2020-08-31
Brocade Network Advisor CRITICAL 9.8
CVE-2018-6446

A vulnerability in Brocade Network Advisor Version Before 14.3.1 could allow an unauthenticated, remote attacker to log in to the JBoss Administratio…

Fix: 14.3.1+
Fix from $2,300 2020-06-29
Ca Api Developer Portal CRITICAL 9.8
CVE-2020-11658

CA API Developer Portal 4.3.1 and earlier handles shared secret keys in an insecure manner, which allows attackers to bypass authorization.

Fix: after 4.3.1
Fix from $2,300 2020-04-15
Ca Api Developer Portal MEDIUM 6.5
CVE-2020-11660

CA API Developer Portal 4.3.1 and earlier contains an access control flaw that allows privileged users to view restricted sensitive information.

Fix: after 4.3.1
Fix from $1,600 2020-04-15
Ca Api Developer Portal HIGH 8.8
CVE-2020-11666

CA API Developer Portal 4.3.1 and earlier contains an access control flaw that allows malicious users to elevate privileges.

Fix: after 4.3.1
Fix from $1,950 2020-04-15
Ca Api Developer Portal MEDIUM 6.1
CVE-2020-11665

CA API Developer Portal 4.3.1 and earlier handles loginRedirect page redirects in an insecure manner, which allows attackers to perform open redirect…

Fix: after 4.3.1
Fix from $1,600 2020-04-15
Ca Api Developer Portal HIGH 8.1
CVE-2020-11661

CA API Developer Portal 4.3.1 and earlier contains an access control flaw that allows privileged users to view and edit user data.

Fix: after 4.3.1
Fix from $1,950 2020-04-15
Ca Api Developer Portal HIGH 7.5
CVE-2020-11662

CA API Developer Portal 4.3.1 and earlier handles requests insecurely, which allows remote attackers to exploit a Cross-Origin Resource Sharing flaw …

Fix: after 4.3.1
Fix from $1,950 2020-04-15
Ca Api Developer Portal MEDIUM 6.1
CVE-2020-11663

CA API Developer Portal 4.3.1 and earlier handles 404 requests in an insecure manner, which allows attackers to perform open redirect attacks.

Fix: after 4.3.1
Fix from $1,600 2020-04-15
Ca Api Developer Portal MEDIUM 6.1
CVE-2020-11664

CA API Developer Portal 4.3.1 and earlier handles homeRedirect page redirects in an insecure manner, which allows attackers to perform open redirect …

Fix: after 4.3.1
Fix from $1,600 2020-04-15
Advanced Secure Gateway MEDIUM 6.5
CVE-2019-18375

The ASG and ProxySG management consoles are susceptible to a session hijacking vulnerability. A remote attacker, with access to the appliance managem…

Fix: 6.7.4.10 / 7.2.0.1+
Fix from $1,600 2020-04-10
Unified Infrastructure Management CRITICAL 9.8
CVE-2020-8010EPSS 49%

CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains an improper ACL handling vulnerability in the robot (con…

Fix: after 20.3.3
Fix from $2,300 2020-02-18
Unified Infrastructure Management CRITICAL 9.8
CVE-2020-8012EPSS 77%

CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a buffer overflow vulnerability in the robot (controller…

Fix: after 20.3.3
Fix from $2,300 2020-02-18
Unified Infrastructure Management HIGH 7.5
CVE-2020-8011

CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a null pointer dereference vulnerability in the robot (c…

Fix: 20.4.0+
Fix from $1,950 2020-02-18
Fabric Operating System HIGH 7.5
CVE-2019-16203

Brocade Fabric OS Versions before v8.2.2a and v8.2.1d could expose the credentials of the remote ESRS server when these credentials are given as a co…

Fix: 8.2.1d / 8.2.2a+
Fix from $1,950 2020-02-05
Fabric Operating System HIGH 7.5
CVE-2019-16204

Brocade Fabric OS Versions before v7.4.2f, v8.2.2a, v8.1.2j and v8.2.1d could expose external passwords, common secrets or authentication keys used b…

Fix: 7.4.2f / 8.1.2j+
Fix from $1,950 2020-02-05
Ca Automic Dollar Universe HIGH 7.8
CVE-2019-19544

CA Automic Dollar Universe 5.3.3 contains a vulnerability, related to the uxdqmsrv binary being setuid root, that allows local attackers to elevate p…

No fix yet
Fix from $1,950 2020-01-08
Ca Automic Sysload CRITICAL 9.8
CVE-2019-19518

CA Automic Sysload 5.6.0 through 6.1.2 contains a vulnerability, related to a lack of authentication on the File Server port, that potentially allows…

Fix: after 6.1.2
Fix from $2,300 2020-01-08
Ca Client Automation HIGH 7.8
CVE-2019-19231

An insecure file access vulnerability exists in CA Client Automation 14.0, 14.1, 14.2, and 14.3 Agent for Windows that can allow a local attacker to …

No fix yet
Fix from $1,950 2019-12-20
Nolio CRITICAL 9.8
CVE-2019-19230

An unsafe deserialization vulnerability exists in CA Release Automation (Nolio) 6.6 with the DataManagement component that can allow a remote attacke…

Patch available
Fix from $2,300 2019-12-09
Symantec Critical System Protection CRITICAL 9.8
CVE-2019-18374

Symantec Critical System Protection (CSP), versions 8.0, 8.0 HF1 & 8.0 MP1, may be susceptible to an authentication bypass vulnerability, which is a …

Mitigation only
Fix from $2,300 2019-11-25
Brocade Sannav HIGH 8.8
CVE-2019-16205

A vulnerability, in Brocade SANnav versions before v2.0, could allow remote attackers to brute-force a valid session ID. The vulnerability is due to …

Fix: 2.0+
Fix from $1,950 2019-11-08
Brocade Sannav HIGH 7.8
CVE-2019-16207

Brocade SANnav versions before v2.0 use a hard-coded password, which could allow local authenticated attackers to access a back-end database and gain…

Fix: 2.0+
Fix from $1,950 2019-11-08
Brocade Sannav HIGH 7.5
CVE-2019-16208

Password-based encryption (PBE) algorithm, of Brocade SANnav versions before v2.0, has a weakness in generating cryptographic keys that may allow an …

Fix: 2.0+
Fix from $1,950 2019-11-08
Brocade Sannav HIGH 7.4
CVE-2019-16209

A vulnerability, in The ReportsTrustManager class of Brocade SANnav versions before v2.0, could allow an attacker to perform a man-in-the-middle atta…

Fix: 2.0+
Fix from $1,950 2019-11-08
Brocade Sannav MEDIUM 5.5
CVE-2019-16206

The authentication mechanism, in Brocade SANnav versions before v2.0, logs plaintext account credentials at the ‘trace’ and the 'debug' logging level…

Fix: 2.0+
Fix from $1,600 2019-11-08
Brocade Sannav MEDIUM 5.5
CVE-2019-16210

Brocade SANnav versions before v2.0, logs plain text database connection password while triggering support save.

Fix: 2.0+
Fix from $1,600 2019-11-08