broadcom security advisories
7 threat alerts tracking vulnerabilities and security advisories that affect broadcom products.
Vulnios monitors broadcom CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent broadcom security news in one place, or click into an individual alert for full detail.
Critical Vulnerability: CVE-2019-3773 — broadcom, oracle — spring_web_services, financial_services_analytical_applications_infrastructure
Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources
criticalCVE-2019-3773Critical Vulnerability: CVE-2019-3774 — broadcom — spring_batch
Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
criticalCVE-2019-3774Critical Vulnerability: CVE-2018-1273 — broadcom, pivotal_software — spring_data_commons, spring_data_rest
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An
criticalCVE-2018-1273Critical Vulnerability: CVE-2015-6853 — broadcom — single_sign-on
The Domino web agent in CA Single Sign-On (aka SSO, formerly SiteMinder) R6, R12.0 before SP3 CR13, R12.0J before SP3 CR1.2, R12.5 before CR5, R12.51 before CR4, and R12.52 before SP1 CR3 allows remot
criticalCVE-2015-6853Critical Vulnerability: CVE-2015-6854 — broadcom — single_sign-on
The non-Domino web agents in CA Single Sign-On (aka SSO, formerly SiteMinder) R6, R12.0 before SP3 CR13, R12.0J before SP3 CR1.2, and R12.5 before CR5 allow remote attackers to cause a denial of servi
criticalCVE-2015-6854Critical Vulnerability: CVE-2017-9417 — broadcom — bcm43xx_wi-fi_chipset_firmware, bcm4354_wi-fi_chipset
Broadcom BCM43xx Wi-Fi chips allow remote attackers to execute arbitrary code via unspecified vectors, aka the "Broadpwn" issue.
criticalCVE-2017-9417Critical Vulnerability: CVE-2016-8204 — broadcom — brocade_network_advisor
A Directory Traversal vulnerability in FileReceiveServlet in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to upload a malicious file in a se
criticalCVE-2016-8204
Track broadcom exposure across your environment
Vulnios automatically cross-references your asset inventory against new broadcom CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan