Vulnerability Description
An unsafe deserialization vulnerability exists in CA Release Automation (Nolio) 6.6 with the DataManagement component that can allow a remote attacker to execute arbitrary code.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Broadcom | Nolio | 6.6 |
| Linux | Linux Kernel | - |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/155631/CA-Nolio-6.6-Arbitrary-Code-ExecutioThird Party Advisory
- http://seclists.org/fulldisclosure/2019/Dec/16Third Party Advisory
- https://seclists.org/bugtraq/2019/Dec/16Third Party Advisory
- https://techdocs.broadcom.com/us/product-content/recommended-reading/security-noPatchVendor Advisory
- http://packetstormsecurity.com/files/155631/CA-Nolio-6.6-Arbitrary-Code-ExecutioThird Party Advisory
- http://seclists.org/fulldisclosure/2019/Dec/16Third Party Advisory
- https://seclists.org/bugtraq/2019/Dec/16Third Party Advisory
- https://techdocs.broadcom.com/us/product-content/recommended-reading/security-noPatchVendor Advisory
FAQ
What is CVE-2019-19230?
CVE-2019-19230 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An unsafe deserialization vulnerability exists in CA Release Automation (Nolio) 6.6 with the DataManagement component that can allow a remote attacker to execute arbitrary code.
How severe is CVE-2019-19230?
CVE-2019-19230 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-19230?
Check the references section above for vendor advisories and patch information. Affected products include: Broadcom Nolio, Linux Linux Kernel, Microsoft Windows.