📦

service_desk_manager

Vendor: ca

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 0 Remote Access
Total CVEs 36 Total Indexed
Avg. EPSS 0.46% Exploit Prob.
Latest CVE CVE-2018-19635 Jan 22

Security Vulnerability Index

Page 1 / 4
9.8 CVSS

CA Service Desk Manager 14.1 and 17 contain a vulnerability that can allow a malicious actor to escalate privileges in the user interface.

EPSS: 0.49%
7.5 CVSS

CA Service Desk Manager 14.1 and 17 contain a vulnerability that can allow a malicious actor to access survey information.

EPSS: 0.26%
6.1 CVSS

Cross-site scripting (XSS) vulnerability in CA Service Desk Manager (formerly CA Service Desk) 12.9 and 14.1 allows remote attackers to inject arbitrary web script or HTML via the QBE.EQ.REF_NUM parameter.

EPSS: 0.37%
8.1 CVSS

RESTful web services in CA Service Desk Manager 12.9 and CA Service Desk Management 14.1 might allow remote authenticated users to read or modify task information by leveraging incorrect permissions applied to a RESTful request.

EPSS: 0.71%