Vulnerabilities > CVE-2018-15691 - Deserialization of Untrusted Data vulnerability in Broadcom Release Automation 6.3/6.4/6.5

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
broadcom
CWE-502
critical
exploit available

Summary

Insecure deserialization of a specially crafted serialized object, in CA Release Automation 6.5 and earlier, allows attackers to potentially execute arbitrary code.

Vulnerable Configurations

Part Description Count
Application
Broadcom
3

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionCA Release Automation NiMi 6.5 - Remote Command Execution. CVE-2018-15691. Remote exploit for Java platform
fileexploits/java/remote/45425.py
idEDB-ID:45425
last seen2018-10-07
modified2018-09-17
platformjava
port
published2018-09-17
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/45425/
titleCA Release Automation NiMi 6.5 - Remote Command Execution
typeremote

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/149427/caran65-exec.txt
idPACKETSTORM:149427
last seen2018-09-19
published2018-09-19
reporterJakub Palaczynski
sourcehttps://packetstormsecurity.com/files/149427/CA-Release-Automation-NiMi-6.5-Remote-Command-Execution.html
titleCA Release Automation NiMi 6.5 Remote Command Execution