Broadcom Ehealth vulnerabilities
3 known vulnerabilities affecting broadcom/ehealth.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3
Vulnerabilities
Page 1 of 1
CVE-2021-28248HIGHCVSS 7.5≤ 6.3.2.122021-03-26
CVE-2021-28248 [HIGH] CWE-307 CVE-2021-28248: CA eHealth Performance Manager through 6.3.2.12 is affected by Improper Restriction of Excessive Aut
CA eHealth Performance Manager through 6.3.2.12 is affected by Improper Restriction of Excessive Authentication Attempts. An attacker is able to perform an arbitrary number of /web/frames/ authentication attempts using different passwords, and eventually gain access to a targeted account, NOTE: This vulnerability only affects products that are no long
nvd
CVE-2021-28246HIGHCVSS 7.8≤ 6.3.2.122021-03-26
CVE-2021-28246 [HIGH] CWE-426 CVE-2021-28246: CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a Dynamicall
CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a Dynamically Linked Shared Object Library. A regular user must create a malicious library in the writable RPATH, to be dynamically linked when the emtgtctl2 executable is run. The code in the library will be executed as the ehealth user. NOTE: This vulnerability o
nvd
CVE-2016-6152HIGHCVSS 8.8v6.3v6.3.1+13 more2016-07-26
CVE-2016-6152 [HIGH] CVE-2016-6152: CA eHealth 6.2.x and 6.3.x before 6.3.2.13 allows remote authenticated users to cause a denial of se
CA eHealth 6.2.x and 6.3.x before 6.3.2.13 allows remote authenticated users to cause a denial of service or possibly execute arbitrary commands via unspecified vectors.
nvd