First published: Thu Aug 30 2018(Updated: )
Unprotected storage of credentials in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows attackers to access sensitive information.
Credit: vuln@ca.com
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom Project Portfolio Management | <=14.3 | |
Broadcom Project Portfolio Management | =14.4 | |
Broadcom Project Portfolio Management | =15.1 | |
Broadcom Project Portfolio Management | =15.2-cumulative_patch_5 | |
Broadcom Project Portfolio Management | =15.3-cumulative_patch_2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-13822 is considered a critical vulnerability due to unprotected storage of sensitive credentials.
To mitigate CVE-2018-13822, upgrade to CA PPM version 15.3 CP3 or later, which addresses the credential storage issue.
CVE-2018-13822 affects CA PPM versions 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below.
CVE-2018-13822 allows attackers to access sensitive information stored in unprotected credentials.
There are no official workarounds for CVE-2018-13822; upgrading to a fixed version is the recommended action.