CVE-2018-15691

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
30/08/2018
Last modified:
12/04/2021

Description

Insecure deserialization of a specially crafted serialized object, in CA Release Automation 6.5 and earlier, allows attackers to potentially execute arbitrary code.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:broadcom:release_automation:*:*:*:*:*:*:*:* 6.3 (including) 6.3.0.9945 (excluding)
cpe:2.3:a:broadcom:release_automation:*:*:*:*:*:*:*:* 6.4 (including) 6.4.0.10119 (excluding)
cpe:2.3:a:broadcom:release_automation:*:*:*:*:*:*:*:* 6.5 (including) 6.5.0.10080 (excluding)