Back to Database
Status published
Critical
CVE-2019-19230
An unsafe deserialization vulnerability exists in CA Release Automation (Nolio)...
Vulnerability Description
An unsafe deserialization vulnerability exists in CA Release Automation (Nolio) 6.6 with the DataManagement component that can allow a remote attacker to execute arbitrary code.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-19230
Credits & Attribution
No credits recorded in the NVD database.
References
- https://techdocs.broadcom.com/us/product-content/recommended-reading/security-notices/ca20191209-01-security-notice-for-ca-nolio-release-automation.html?r=2
- http://seclists.org/fulldisclosure/2019/Dec/16
- https://seclists.org/bugtraq/2019/Dec/16
- http://packetstormsecurity.com/files/155631/CA-Nolio-6.6-Arbitrary-Code-Execution.html
More from CA Technologies, A Broadcom Company
View All →CVE-2020-29478
CA Service Catalog 17.2 and 17.3 contain a vulnerability in...
High
7.5
CVE-2019-7394
A privilege escalation vulnerability in the administrative user interface of...
High
8.8
CVE-2019-7393
A UI redress vulnerability in the administrative user interface of...
Medium
4.3
CVE-2019-13657
CA Performance Management 3.5.x, 3.6.x before 3.6.9, and 3.7.x before...
Critical
9.8
Affected Vendor
CA Technologies, A Broadcom Company
View all reports →Affected Software
CA Release Automation
Vulnerable Versions:
6.6
Timeline
Official Publish:
December 9th, 2019
Last Modified:
September 17th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H