ZeroHour

CVE-2018-13826

CVSS 3.0
9.1 critical
EPSS
2%p78
Published
()
Modified
Description

An XML external entity vulnerability in the XOG functionality, in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows remote attackers to conduct server side request forgery attacks.

Vendors
broadcomca
Products
project portfolio management
Weakness
CWE-611
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.