CA Technologies - A Broadcom Company
Self-Reporting Analysis
Of all the CVEs published by CA Technologies - A Broadcom Company as a CNA, 22.0% affect products that CA Technologies - A Broadcom Company develops as a vendor.
Of all the CVEs published that affect products developed by CA Technologies - A Broadcom Company, 14.5% are self-published by CA Technologies - A Broadcom Company as a CNA.
Trends Over Time
The number and severity of CVEs published by CA Technologies - A Broadcom Company over time
Top CVEs
All CVEs published by CA Technologies - A Broadcom Company as a CNA, regardless of affected vendor or product.
91 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-8012CRITICAL CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a buffer overflow vulnerability in the robot (controller) component. A remote attacker | Feb 18, 2020 | 9.8 | 86 | NO | YES |
CVE-2020-8010CRITICAL CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains an improper ACL handling vulnerability in the robot (controller) component. A remote at | Feb 18, 2020 | 9.8 | 70 | NO | YES |
CVE-2018-9022CRITICAL An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary code or commands by poisoning a configuration | Jun 18, 2018 | 9.8 | 53 | NO | YES |
CVE-2018-9021CRITICAL An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary commands with specially crafted requests. | Jun 18, 2018 | 9.8 | 52 | NO | YES |
CVE-2018-15691CRITICAL Insecure deserialization of a specially crafted serialized object, in CA Release Automation 6.5 and earlier, allows attackers to potentially execute arbitrary code. | Aug 30, 2018 | 9.8 | 51 | NO | YES |
CVE-2015-4664CRITICAL An improper input validation vulnerability in CA Privileged Access Manager 2.4.4.4 and earlier allows remote attackers to execute arbitrary commands. | Jun 18, 2018 | 9.8 | 45 | NO | YES |
CVE-2026-8370HIGH Execution with unnecessary privileges vulnerability in Broadcom Automic Automation Agent Unix on Linux x64, Linux Power 64 BE, Linux Power 64 LE, zLinux (zSeries), AIX, Solaris x64 | May 19, 2026 | 8.5 | 34 | NO | NO |
CVE-2025-4971HIGH Broadcom Automic
Automation Agent Unix versions <
24.3.0 HF4 and < 21.0.13 HF1 allow low privileged users who have execution
rights on the agent executable to escalate their privil | May 20, 2025 | 8.5 | 33 | NO | YES |
CVE-2019-13656CRITICAL An access vulnerability in CA Common Services DIA of CA Technologies Client Automation 14 and Workload Automation AE 11.3.5, 11.3.6 allows a remote attacker to execute arbitrary co | Sep 6, 2019 | 9.8 | 32 | NO | NO |
CVE-2018-8954CRITICAL CA Workload Control Center before r11.4 SP6 allows remote attackers to execute arbitrary code via a crafted HTTP request. | Apr 11, 2018 | 9.8 | 32 | NO | NO |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this cna scope (91 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID published by CA Technologies - A Broadcom Company as a CNA.
Media Mentions
Media articles that mention a CVE ID published by CA Technologies - A Broadcom Company as a CNA — matched by CVE ID, not by organization name.