SB2018040204 - Multiple vulnerabilities in CA Workload Automation AE and CA Workload Control Center



SB2018040204 - Multiple vulnerabilities in CA Workload Automation AE and CA Workload Control Center

Published: April 2, 2018

Security Bulletin ID SB2018040204
Severity
High
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) SQL injection (CVE-ID: CVE-2018-8953)

The vulnerability allows a remote authenticated attacker to execute arbitrary SQL commands in web application database.

The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can send a specially crafted HTTP request to vulnerable script and execute arbitrary SQL commands in web application database.

Successful exploitation of the vulnerability may allow an attacker to gain administrative access to vulnerable web application.


2) Remote code execution (CVE-ID: CVE-2018-8954)

The vulnerability allows a remote authenticated attacker to execute arbitrary code on the target system.

The vulnerability exists due to a flaw in Apache MyFaces component. A remote attacker can execute arbitrary code with elevated privileges.


Remediation

Install update from vendor's website.