CVE-2018-8954

CRITICAL

CA Workload Control Center < r11.4 - Improper Input Validation

Title source: rule

Description

CA Workload Control Center before r11.4 SP6 allows remote attackers to execute arbitrary code via a crafted HTTP request.

Scores

CVSS v3 9.8
EPSS 0.0474
EPSS Percentile 89.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-20
Status published

Affected Products (6)

ca/workload_control_center < r11.4
ca/workload_control_center
ca/workload_control_center
ca/workload_control_center
ca/workload_control_center
ca/workload_control_center

Timeline

Published Apr 11, 2018
Tracked Since Feb 18, 2026