SQL injection vulnerability in CA Release Automation (formerly iTKO LISA Release Automation) before 4.7.1 b448 allows remote authenticated users to execute arbitrary SQL commands via a crafted query.
References
Configurations
History
21 Nov 2024, 02:18
Type | Values Removed | Values Added |
---|---|---|
References | () http://seclists.org/fulldisclosure/2014/Dec/55 - | |
References | () http://securitytracker.com/id?1031375 - | |
References | () http://www.ca.com/us/support/ca-support-online/product-content/recommended-reading/security-notices/ca20141215-01-security-notice-for-ca-lisa-release-automation.aspx - Vendor Advisory | |
References | () http://www.kb.cert.org/vuls/id/343060 - Third Party Advisory, US Government Resource | |
References | () http://www.securityfocus.com/archive/1/534246/100/0/threaded - |
Information
Published : 2014-12-16 23:59
Updated : 2024-11-21 02:18
NVD link : CVE-2014-8248
Mitre link : CVE-2014-8248
CVE.ORG link : CVE-2014-8248
JSON object : View
Products Affected
broadcom
- release_automation
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')