Vulnerability Details CVE-2018-13824
Insufficient input sanitization of two parameters in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows remote attackers to execute SQL injection attacks.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 71.3%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2018-13824
-
cpe:2.3:a:broadcom:project_portfolio_management:14.2
-
cpe:2.3:a:broadcom:project_portfolio_management:14.3
-
cpe:2.3:a:broadcom:project_portfolio_management:14.4
-
cpe:2.3:a:broadcom:project_portfolio_management:15.1
-
cpe:2.3:a:ca:project_portfolio_management:15.2
-
cpe:2.3:a:ca:project_portfolio_management:15.3