Vulnerability Details CVE-2022-22689
CA Harvest Software Change Manager versions 13.0.3, 13.0.4, 14.0.0, and 14.0.1, contain a vulnerability in the CSV export functionality, due to insufficient input validation, that can allow a privileged user to potentially execute arbitrary code or commands.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.023
EPSS Ranking 83.7%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.5
Products affected by CVE-2022-22689
-
cpe:2.3:a:broadcom:ca_harvest_software_change_manager:13.0.3
-
cpe:2.3:a:broadcom:ca_harvest_software_change_manager:13.0.4
-
cpe:2.3:a:broadcom:ca_harvest_software_change_manager:14.0.0
-
cpe:2.3:a:broadcom:ca_harvest_software_change_manager:14.0.1