Back to Database
Status published
Critical
CVE-2019-13657
CA Performance Management 3.5.x, 3.6.x before 3.6.9, and 3.7.x before...
Vulnerability Description
CA Performance Management 3.5.x, 3.6.x before 3.6.9, and 3.7.x before 3.7.4 have a default credential vulnerability that can allow a remote attacker to execute arbitrary commands and compromise system security.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-13657
Credits & Attribution
No credits recorded in the NVD database.
References
- https://seclists.org/bugtraq/2019/Oct/26
- http://packetstormsecurity.com/files/154904/CA-Performance-Management-Arbitary-Command-Execution.html
- https://techdocs.broadcom.com/us/product-content/recommended-reading/security-notices/ca-20191015-01-security-notice-for-ca-performance-management.html
- http://packetstormsecurity.com/files/154904/CA-Performance-Management-Arbitrary-Command-Execution.html
- http://seclists.org/fulldisclosure/2019/Oct/37
More from CA Technologies, A Broadcom Company
View All →CVE-2020-29478
CA Service Catalog 17.2 and 17.3 contain a vulnerability in...
High
7.5
CVE-2019-7394
A privilege escalation vulnerability in the administrative user interface of...
High
8.8
CVE-2019-7393
A UI redress vulnerability in the administrative user interface of...
Medium
4.3
CVE-2019-19230
An unsafe deserialization vulnerability exists in CA Release Automation (Nolio)...
Critical
9.8
Affected Vendor
CA Technologies, A Broadcom Company
View all reports →Affected Software
CA Performance Management
Vulnerable Versions:
3.5.x, 3.6.x before 3.6.9, 3.7.x before 3.7.4
Timeline
Official Publish:
October 17th, 2019
Last Modified:
September 17th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H