Multiple cross-site scripting (XSS) vulnerabilities in CA Release Automation (formerly LISA Release Automation) 5.0.2 before 5.0.2-227, 5.5.1 before 5.5.1-1616, 5.5.2 before 5.5.2-434, and 6.1.0 before 6.1.0-1026 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
2016-06-29T01:59:01.370
2025-04-12T10:46:40.837
Deferred
CVSSv3.0: 6.1 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | broadcom | release_automation | < 5.0.2-227 | Yes |
Application | broadcom | release_automation | < 5.5.1-1616 | Yes |
Application | broadcom | release_automation | < 5.5.2-434 | Yes |
Application | broadcom | release_automation | < 6.1.0-1026 | Yes |