CVE-2018-8954: Input Validation
Published Apr 11, 2018
·Updated
CA Workload Control Center before r11.4 SP6 allows remote attackers to execute arbitrary code via a crafted HTTP request.
Affected Software
6 affected components
CA Workload Control Center<=r11.4
CA Workload Control Center=sp1
CA Workload Control Center=sp2
CA Workload Control Center=sp3
CA Workload Control Center=sp4
CA Workload Control Center=sp5
Event History
Apr 11, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionWeakness
Data Sourced
via NVD·05:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-8954?
CVE-2018-8954 is considered a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2018-8954?
To mitigate CVE-2018-8954, upgrade CA Workload Control Center to version r11.4 SP6 or later.
3
Who is affected by CVE-2018-8954?
CVE-2018-8954 affects all versions of CA Workload Control Center prior to r11.4 SP6.
4
What type of attacks can be performed using CVE-2018-8954?
CVE-2018-8954 allows remote attackers to execute arbitrary code via crafted HTTP requests.
5
Is CVE-2018-8954 being actively exploited?
There have been reports of active exploitation attempts targeting CVE-2018-8954.