CVE-2015-8698: Broadcom Release Automation
High severity, CVSS 7.1. EPSS: 0.6% chance of exploitation in the next 30 days.
CA Release Automation (formerly LISA Release Automation) 5.0.2 before 5.0.2-227, 5.5.1 before 5.5.1-1616, 5.5.2 before 5.5.2-434, and 6.1.0 before 6.1.0-1026 allows remote attackers to read arbitrary files or cause a denial of service via a request containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Affected products
- Broadcom Release Automation: from 5.0.2, before 5.0.2-227 (fixed in 5.0.2-227); from 5.5.1, before 5.5.1-1616 (fixed in 5.5.1-1616); from 5.5.2, before 5.5.2-434 (fixed in 5.5.2-434); from 6.1.0, before 6.1.0-1026 (fixed in 6.1.0-1026)
Published 2016-06-29. Last modified 2026-06-17.