« Volver al listado

CVE-2018-15691

Estado: ModificadaCrítica (9.8)—

Insecure deserialization of a specially crafted serialized object, in CA Release Automation 6.5 and earlier, allows attackers to potentially execute arbitrary code.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2018-15691",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "vuln@ca.com",
      "affectedData": [
        {
          "vendor": "CA Technologies",
          "product": "Release Automation",
          "versions": [
            {
              "status": "affected",
              "version": "6.5 and earlier"
            }
          ]
        }
      ]
    }
  ],
  "published": "2018-08-30T14:29:01.737",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/105197",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "vuln@ca.com"
    },
    {
      "url": "http://www.securitytracker.com/id/1041591",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "vuln@ca.com"
    },
    {
      "url": "https://support.ca.com/us/product-content/recommended-reading/security-notices/ca20180829-03--security-notice-for-ca-release-automation.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "vuln@ca.com"
    },
    {
      "url": "https://www.exploit-db.com/exploits/45425/",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "vuln@ca.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/105197",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id/1041591",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.ca.com/us/product-content/recommended-reading/security-notices/ca20180829-03--security-notice-for-ca-release-automation.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.exploit-db.com/exploits/45425/",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-502"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Insecure deserialization of a specially crafted serialized object, in CA Release Automation 6.5 and earlier, allows attackers to potentially execute arbitrary code."
    },
    {
      "lang": "es",
      "value": "La deserialización insegura de un objeto serializado especialmente manipulado en CA Release Automation en versiones 6.5 y anteriores, permite que los atacantes puedan ejecutar código arbitrario."
    }
  ],
  "lastModified": "2026-06-17T01:42:56.573",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:broadcom:release_automation:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9185F1CB-6A09-46E6-A3FA-2525F382366A",
              "versionEndExcluding": "6.3.0.9945",
              "versionStartIncluding": "6.3"
            },
            {
              "criteria": "cpe:2.3:a:broadcom:release_automation:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "294D1648-D1A5-476A-907E-BC4D1F1E2877",
              "versionEndExcluding": "6.4.0.10119",
              "versionStartIncluding": "6.4"
            },
            {
              "criteria": "cpe:2.3:a:broadcom:release_automation:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B9321960-9802-4B55-9B55-FEE0A5A1BBD0",
              "versionEndExcluding": "6.5.0.10080",
              "versionStartIncluding": "6.5"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "vuln@ca.com"
}