PT-2019-13465 · Ca · Ca Performance Management

Published

2019-10-17

·

Updated

2019-10-24

·

CVE-2019-13657

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CA Performance Management versions 3.5.x through 3.6.8 and versions 3.7.x through 3.7.3
Description The issue allows a remote attacker to execute arbitrary commands and compromise system security due to a default credential vulnerability.
Recommendations For versions 3.5.x, update to a version after 3.5.x. For versions 3.6.x, update to version 3.6.9 or later. For versions 3.7.x, update to version 3.7.4 or later.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-13657

Affected Products

Ca Performance Management