CVE-2018-15691: Broadcom Release Automation

Critical severity, CVSS 9.8. EPSS: 16.8% chance of exploitation in the next 30 days.

Insecure deserialization of a specially crafted serialized object, in CA Release Automation 6.5 and earlier, allows attackers to potentially execute arbitrary code.

Affected products

  • Broadcom Release Automation: from 6.3, before 6.3.0.9945 (fixed in 6.3.0.9945); from 6.4, before 6.4.0.10119 (fixed in 6.4.0.10119); from 6.5, before 6.5.0.10080 (fixed in 6.5.0.10080)

Published 2018-08-30. Last modified 2026-06-17.