First published: Wed Apr 11 2018(Updated: )
CA Workload Control Center before r11.4 SP6 allows remote attackers to execute arbitrary code via a crafted HTTP request.
Credit: vuln@ca.com
Affected Software | Affected Version | How to fix |
---|---|---|
CA Workload Control Center | <=r11.4 | |
CA Workload Control Center | =sp1 | |
CA Workload Control Center | =sp2 | |
CA Workload Control Center | =sp3 | |
CA Workload Control Center | =sp4 | |
CA Workload Control Center | =sp5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8954 is considered a critical vulnerability due to its potential for remote code execution.
To mitigate CVE-2018-8954, upgrade CA Workload Control Center to version r11.4 SP6 or later.
CVE-2018-8954 affects all versions of CA Workload Control Center prior to r11.4 SP6.
CVE-2018-8954 allows remote attackers to execute arbitrary code via crafted HTTP requests.
There have been reports of active exploitation attempts targeting CVE-2018-8954.