Vulnerabilities > CA

DATE CVE VULNERABILITY TITLE RISK
2021-03-26 CVE-2021-28250 Improper Privilege Management vulnerability in CA Ehealth Performance Manager
** UNSUPPORTED WHEN ASSIGNED ** CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a setuid (and/or setgid) file.
local
low complexity
ca CWE-269
4.6
2021-03-26 CVE-2021-28249 Improper Privilege Management vulnerability in CA Ehealth Performance Manager
** UNSUPPORTED WHEN ASSIGNED ** CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a Dynamically Linked Shared Object Library.
local
low complexity
ca CWE-269
7.2
2021-03-26 CVE-2021-28248 Improper Restriction of Excessive Authentication Attempts vulnerability in CA Ehealth
** UNSUPPORTED WHEN ASSIGNED ** CA eHealth Performance Manager through 6.3.2.12 is affected by Improper Restriction of Excessive Authentication Attempts.
network
low complexity
ca CWE-307
5.0
2021-03-26 CVE-2021-28247 Cross-Site Scripting vulnerability in CA Ehealth Performance Manager
** UNSUPPORTED WHEN ASSIGNED ** CA eHealth Performance Manager through 6.3.2.12 is affected by Cross Site Scripting (XSS).
network
ca CWE-79
3.5
2021-03-26 CVE-2021-28246 Untrusted Search Path vulnerability in CA Ehealth
** UNSUPPORTED WHEN ASSIGNED ** CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a Dynamically Linked Shared Object Library.
local
ca CWE-426
4.4
2019-05-28 CVE-2019-7394 Permissions, Privileges, and Access Controls vulnerability in CA Risk Authentication and Strong Authentication
A privilege escalation vulnerability in the administrative user interface of CA Technologies CA Strong Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 7.1.x and CA Risk Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 3.1.x allows an authenticated attacker to gain additional privileges in some cases where an account has customized and limited privileges.
network
low complexity
ca CWE-264
6.5
2019-05-28 CVE-2019-7393 Information Exposure vulnerability in CA Risk Authentication and Strong Authentication
A UI redress vulnerability in the administrative user interface of CA Technologies CA Strong Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 7.1.x and CA Risk Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 3.1.x may allow a remote attacker to gain sensitive information in some cases.
network
low complexity
ca CWE-200
4.0
2019-01-22 CVE-2018-19635 CA Service Desk Manager 14.1 and 17 contain a vulnerability that can allow a malicious actor to escalate privileges in the user interface.
network
low complexity
broadcom ca
7.5
2019-01-22 CVE-2018-19634 CA Service Desk Manager 14.1 and 17 contain a vulnerability that can allow a malicious actor to access survey information.
network
low complexity
broadcom ca
5.0
2018-08-30 CVE-2018-13826 XXE vulnerability in multiple products
An XML external entity vulnerability in the XOG functionality, in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows remote attackers to conduct server side request forgery attacks.
network
low complexity
broadcom ca CWE-611
6.4