Vulnerability index

Browse CVEs

55 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ehealth Performance Manager HIGH 8.8
CVE-2021-28249

CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a Dynamically Linked Shared Object Library. To exploit the vu…

Fix: after 6.3.2.12
Fix from $1,950 2021-03-26
Ehealth Performance Manager HIGH 7.8
CVE-2021-28250

CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a setuid (and/or setgid) file. When a component is run as an …

Fix: after 6.3.2.12
Fix from $1,950 2021-03-26
Ehealth Performance Manager MEDIUM 5.4
CVE-2021-28247

CA eHealth Performance Manager through 6.3.2.12 is affected by Cross Site Scripting (XSS). The impact is: An authenticated remote user is able to inj…

Fix: after 6.3.2.12
Fix from $1,600 2021-03-26
Risk Authentication HIGH 8.8
CVE-2019-7394

A privilege escalation vulnerability in the administrative user interface of CA Technologies CA Strong Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 7.1…

Fix: after 8.2.1
Fix from $1,950 2019-05-28
Unified Infrastructure Management CRITICAL 9.8
CVE-2018-13821

A lack of authentication, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows remote attackers to conduct a variety of attacks, inc…

Patch available
Fix from $2,300 2018-08-30
Unified Infrastructure Management HIGH 7.5
CVE-2018-13819

A hardcoded secret key, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows attackers to access sensitive information.

Mitigation only
Fix from $1,950 2018-08-30
Unified Infrastructure Management HIGH 7.5
CVE-2018-13820

A hardcoded passphrase, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows attackers to access sensitive information.

No fix yet
Fix from $1,950 2018-08-30
Ca Privileged Access Manager MEDIUM 6.1
CVE-2018-9027

A reflected cross-site scripting vulnerability in CA Privileged Access Manager 2.x allows remote attackers to execute malicious script with a special…

Mitigation only
Fix from $1,600 2018-06-18
Spectrum HIGH 7.5
CVE-2018-6589

CA Spectrum 10.1 prior to 10.01.02.PTF_10.1.239 and 10.2.x prior to 10.2.3 allows remote attackers to cause a denial of service via unspecified vecto…

Fix: 10.01.02.ptf_10.1.239 / 10.2.3+
Fix from $1,950 2018-05-01
Workload Control Center CRITICAL 9.8
CVE-2018-8954EPSS 7%

CA Workload Control Center before r11.4 SP6 allows remote attackers to execute arbitrary code via a crafted HTTP request.

Mitigation only
Fix from $2,300 2018-04-11
Workload Automation Ae HIGH 8.8
CVE-2018-8953

CA Workload Automation AE before r11.3.6 SP7 allows remote attackers to a perform SQL injection via a crafted HTTP request.

Mitigation only
Fix from $1,950 2018-04-11
Api Developer Portal MEDIUM 6.1
CVE-2018-6586

CA API Developer Portal 3.5 up to and including 3.5 CR6 has a stored cross-site scripting vulnerability related to profile picture processing.

Patch available
Fix from $1,600 2018-03-29
Api Developer Portal MEDIUM 6.1
CVE-2018-6587

CA API Developer Portal 3.5 up to and including 3.5 CR6 has a reflected cross-site scripting vulnerability related to the widgetID variable.

Patch available
Fix from $1,600 2018-03-29
Api Developer Portal MEDIUM 6.1
CVE-2018-6588

CA API Developer Portal 3.5 up to and including 3.5 CR5 has a reflected cross-site scripting vulnerability related to the apiExplorer.

Patch available
Fix from $1,600 2018-03-29
Identity Governance MEDIUM 5.4
CVE-2017-9394

A stored cross-site scripting vulnerability in CA Identity Governance 12.6 allows remote authenticated attackers to display HTML or execute script in…

Mitigation only
Fix from $1,600 2017-11-14
Identity Manager CRITICAL 9.8
CVE-2017-9393

CA Identity Manager r12.6 to r12.6 SP8, 14.0, and 14.1 allows remote attackers to potentially identify passwords of locked accounts through an exhaus…

Mitigation only
Fix from $2,300 2017-09-22
Client Automation MEDIUM 5.5
CVE-2017-8391

The OS Installation Management component in CA Client Automation r12.9, r14.0, and r14.0 SP1 places an encrypted password into a readable local file …

Mitigation only
Fix from $1,600 2017-05-06
Unified Infrastructure Management HIGH 7.5
CVE-2016-9165

The get_sessions servlet in CA Unified Infrastructure Management (formerly CA Nimsoft Monitor) before 8.5 and CA Unified Infrastructure Management Sn…

Fix: after 8.47
Fix from $1,950 2017-03-20
Unified Infrastructure Management HIGH 7.5
CVE-2016-9164EPSS 5%

Directory traversal vulnerability in diag.jsp file in CA Unified Infrastructure Management (formerly CA Nimsoft Monitor) 8.4 SP1 and earlier and CA U…

Fix: after 8.4
Fix from $1,950 2017-03-07
Service Desk Manager MEDIUM 6.1
CVE-2016-9148

Cross-site scripting (XSS) vulnerability in CA Service Desk Manager (formerly CA Service Desk) 12.9 and 14.1 allows remote attackers to inject arbitr…

No fix yet
Fix from $1,600 2017-03-07
Service Desk Management HIGH 8.1
CVE-2016-10086

RESTful web services in CA Service Desk Manager 12.9 and CA Service Desk Management 14.1 might allow remote authenticated users to read or modify tas…

Patch available
Fix from $1,950 2017-01-18
Ehealth HIGH 8.8
CVE-2016-6151

CA eHealth 6.2.x allows remote authenticated users to cause a denial of service or possibly execute arbitrary commands via unspecified vectors.

Patch available
Fix from $1,950 2016-07-26
Cloud Service Management HIGH 7.5
CVE-2014-8474

CA Cloud Service Management (CSM) before Summer 2014 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or caus…

Fix: after 2014
Fix from $1,950 2014-11-04
Cloud Service Management MEDIUM 6.8
CVE-2014-8472

CA Cloud Service Management (CSM) before Summer 2014 does not properly verify authentication tokens from an Identity Provider, which allows user-assi…

Fix: after 2014
Fix from $1,600 2014-11-04
Cloud Service Management MEDIUM 6.8
CVE-2014-8473

Cross-site request forgery (CSRF) vulnerability in CA Cloud Service Management (CSM) before Summer 2014 allows remote attackers to hijack the authent…

Fix: after 2014
Fix from $1,600 2014-11-04
Erwin Web Portal HIGH 7.5
CVE-2014-2210EPSS 5%

Multiple directory traversal vulnerabilities in CA ERwin Web Portal 9.5 allow remote attackers to obtain sensitive information, bypass intended acces…

Patch available
Fix from $1,950 2014-04-04
Identityminder HIGH 10.0
CVE-2012-6299

Unspecified vulnerability in CA IdentityMinder r12.0 through CR16, r12.5 before SP15, and r12.6 GA allows remote attackers to bypass intended access …

Mitigation only
Fix from $1,950 2012-12-26
Identityminder HIGH 10.0
CVE-2012-6298

Unspecified vulnerability in CA IdentityMinder r12.0 through CR16, r12.5 before SP15, and r12.6 GA allows remote attackers to execute arbitrary comma…

Mitigation only
Fix from $1,950 2012-12-26
Xcom Data Transport HIGH 10.0
CVE-2012-5973

CA XCOM Data Transport r11.0 and r11.5 on UNIX and Linux allows remote attackers to execute arbitrary commands via a crafted request.

Mitigation only
Fix from $1,950 2012-12-10
Internet Security Suite 2010 MEDIUM 6.2
CVE-2010-5156

Race condition in CA Internet Security Suite Plus 2010 6.0.0.272 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute da…

Mitigation only
Fix from $1,600 2012-08-25