CA Harvest Software Change Manager versions 13.0.3, 13.0.4, 14.0.0, and 14.0.1, contain a vulnerability in the CSV export functionality, due to insufficient input validation, that can allow a privileged user to potentially execute arbitrary code or commands.
2022-02-04T23:15:13.017
2024-11-21T06:47:16.437
Modified
CVSSv3.1: 8.8 (HIGH)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | broadcom | ca_harvest_software_change_manager | 13.0.3 | Yes |
Application | broadcom | ca_harvest_software_change_manager | 13.0.4 | Yes |
Application | broadcom | ca_harvest_software_change_manager | 14.0.0 | Yes |
Application | broadcom | ca_harvest_software_change_manager | 14.0.1 | Yes |