vendor:
CA Release Automation
by:
Jakub Palaczynski, Maciej Grabiec
9.8
CVSS
CRITICAL
Remote Command Execution
94
CWE
Product Name: CA Release Automation
Affected Version From: CA Release Automation (NiMi) 5.X
Affected Version To: CA Release Automation (NiMi) 6.5
Patch Exists: NO
Related CWE: CVE-2018-15691
CPE: a:ca:release_automation:5.0
Platforms Tested:
2016
CA Release Automation NiMi 6.5 – Remote Command Execution
CA Release Automation (NiMi) Remote Command Execution via Deserialization. Payloads generated using CommonsCollections1 from ysoserial work correctly. Proof of Concept exploits NiMi service if security is turned off.
Mitigation:
Enable security on the NiMi service to prevent remote command execution.