CVE-2018-8953: SQL Injection
Published Apr 11, 2018
·Updated
CA Workload Automation AE before r11.3.6 SP7 allows remote attackers to a perform SQL injection via a crafted HTTP request.
Affected Software
7 affected components
CA Workload Automation AE<=r11.3.6
CA Workload Automation AE=r11.3.6-sp1
CA Workload Automation AE=r11.3.6-sp2
CA Workload Automation AE=r11.3.6-sp3
CA Workload Automation AE=r11.3.6-sp4
CA Workload Automation AE=r11.3.6-sp5
CA Workload Automation AE=r11.3.6-sp6
Event History
Apr 11, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionWeakness
Data Sourced
via NVD·05:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-8953?
CVE-2018-8953 is classified as a critical vulnerability due to its potential for remote exploitation and SQL injection.
2
How do I fix CVE-2018-8953?
To fix CVE-2018-8953, update CA Workload Automation AE to version r11.3.6 SP7 or a later release.
3
What are the impacts of CVE-2018-8953?
The impact of CVE-2018-8953 can lead to unauthorized access to the database and manipulation of sensitive data.
4
Which versions are affected by CVE-2018-8953?
CVE-2018-8953 affects CA Workload Automation AE versions prior to r11.3.6 SP7, including all service packs from SP1 to SP6.
5
Can CVE-2018-8953 be exploited remotely?
Yes, CVE-2018-8953 can be exploited remotely via crafted HTTP requests, allowing attackers to execute SQL queries.