Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.8
CVE-2021-28249
CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a Dynamically Linked Shared Object Library. To exploit the vu…
Ehealth Performance Manager
after 6.3.2.12
HIGH 7.8
CVE-2021-28250
CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a setuid (and/or setgid) file. When a component is run as an …
Ehealth Performance Manager
after 6.3.2.12
MEDIUM 5.4
CVE-2021-28247
CA eHealth Performance Manager through 6.3.2.12 is affected by Cross Site Scripting (XSS). The impact is: An authenticated remote user is able to inj…
Ehealth Performance Manager
after 6.3.2.12
HIGH 8.8
CVE-2019-7394
A privilege escalation vulnerability in the administrative user interface of CA Technologies CA Strong Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 7.1…
Risk Authentication
after 8.2.1
CRITICAL 9.8
CVE-2018-13821
A lack of authentication, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows remote attackers to conduct a variety of attacks, inc…
Unified Infrastructure Management
Patch available
HIGH 7.5
CVE-2018-13819
A hardcoded secret key, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows attackers to access sensitive information.
Unified Infrastructure Management
Mitigation only
HIGH 7.5
CVE-2018-13820
A hardcoded passphrase, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows attackers to access sensitive information.
Unified Infrastructure Management
No fix yet
MEDIUM 6.1
CVE-2018-9027
A reflected cross-site scripting vulnerability in CA Privileged Access Manager 2.x allows remote attackers to execute malicious script with a special…
Ca Privileged Access Manager
Mitigation only
HIGH 7.5
CVE-2018-6589
CA Spectrum 10.1 prior to 10.01.02.PTF_10.1.239 and 10.2.x prior to 10.2.3 allows remote attackers to cause a denial of service via unspecified vecto…
Spectrum
10.01.02.ptf_10.1.239 / 10.2.3+
CRITICAL 9.8
CVE-2018-8954EPSS 7%
CA Workload Control Center before r11.4 SP6 allows remote attackers to execute arbitrary code via a crafted HTTP request.
Workload Control Center
Mitigation only
HIGH 8.8
CVE-2018-8953
CA Workload Automation AE before r11.3.6 SP7 allows remote attackers to a perform SQL injection via a crafted HTTP request.
Workload Automation Ae
Mitigation only
MEDIUM 6.1
CVE-2018-6586
CA API Developer Portal 3.5 up to and including 3.5 CR6 has a stored cross-site scripting vulnerability related to profile picture processing.
Api Developer Portal
Patch available
MEDIUM 6.1
CVE-2018-6587
CA API Developer Portal 3.5 up to and including 3.5 CR6 has a reflected cross-site scripting vulnerability related to the widgetID variable.
Api Developer Portal
Patch available
MEDIUM 6.1
CVE-2018-6588
CA API Developer Portal 3.5 up to and including 3.5 CR5 has a reflected cross-site scripting vulnerability related to the apiExplorer.
Api Developer Portal
Patch available
MEDIUM 5.4
CVE-2017-9394
A stored cross-site scripting vulnerability in CA Identity Governance 12.6 allows remote authenticated attackers to display HTML or execute script in…
Identity Governance
Mitigation only
CRITICAL 9.8
CVE-2017-9393
CA Identity Manager r12.6 to r12.6 SP8, 14.0, and 14.1 allows remote attackers to potentially identify passwords of locked accounts through an exhaus…
Identity Manager
Mitigation only
MEDIUM 5.5
CVE-2017-8391
The OS Installation Management component in CA Client Automation r12.9, r14.0, and r14.0 SP1 places an encrypted password into a readable local file …
Client Automation
Mitigation only
HIGH 7.5
CVE-2016-9165
The get_sessions servlet in CA Unified Infrastructure Management (formerly CA Nimsoft Monitor) before 8.5 and CA Unified Infrastructure Management Sn…
Unified Infrastructure Management
after 8.47
HIGH 7.5
CVE-2016-9164EPSS 5%
Directory traversal vulnerability in diag.jsp file in CA Unified Infrastructure Management (formerly CA Nimsoft Monitor) 8.4 SP1 and earlier and CA U…
Unified Infrastructure Management
after 8.4
MEDIUM 6.1
CVE-2016-9148
Cross-site scripting (XSS) vulnerability in CA Service Desk Manager (formerly CA Service Desk) 12.9 and 14.1 allows remote attackers to inject arbitr…
Service Desk Manager
No fix yet
HIGH 8.1
CVE-2016-10086
RESTful web services in CA Service Desk Manager 12.9 and CA Service Desk Management 14.1 might allow remote authenticated users to read or modify tas…
Service Desk Management
Patch available
HIGH 8.8
CVE-2016-6151
CA eHealth 6.2.x allows remote authenticated users to cause a denial of service or possibly execute arbitrary commands via unspecified vectors.
Ehealth
Patch available
HIGH 7.5
CVE-2014-8474
CA Cloud Service Management (CSM) before Summer 2014 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or caus…
Cloud Service Management
after 2014
MEDIUM 6.8
CVE-2014-8472
CA Cloud Service Management (CSM) before Summer 2014 does not properly verify authentication tokens from an Identity Provider, which allows user-assi…
Cloud Service Management
after 2014
MEDIUM 6.8
CVE-2014-8473
Cross-site request forgery (CSRF) vulnerability in CA Cloud Service Management (CSM) before Summer 2014 allows remote attackers to hijack the authent…
Cloud Service Management
after 2014
HIGH 7.5
CVE-2014-2210EPSS 5%
Multiple directory traversal vulnerabilities in CA ERwin Web Portal 9.5 allow remote attackers to obtain sensitive information, bypass intended acces…
Erwin Web Portal
Patch available
HIGH 10.0
CVE-2012-6299
Unspecified vulnerability in CA IdentityMinder r12.0 through CR16, r12.5 before SP15, and r12.6 GA allows remote attackers to bypass intended access …
Identityminder
Mitigation only
HIGH 10.0
CVE-2012-6298
Unspecified vulnerability in CA IdentityMinder r12.0 through CR16, r12.5 before SP15, and r12.6 GA allows remote attackers to execute arbitrary comma…
Identityminder
Mitigation only
HIGH 10.0
CVE-2012-5973
CA XCOM Data Transport r11.0 and r11.5 on UNIX and Linux allows remote attackers to execute arbitrary commands via a crafted request.
Xcom Data Transport
Mitigation only
MEDIUM 6.2
CVE-2010-5156
Race condition in CA Internet Security Suite Plus 2010 6.0.0.272 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute da…
Internet Security Suite 2010
Mitigation only