| OSVDB ID | Disclosure Date | Title |
|
42303
Description:
Unknown / Incomplete
|
2007-09-27
|
CA Personal Firewall Unspecified Remote Issue (ZD-00000149)
|
|
42312
Description:
Unknown / Incomplete
|
2007-12-12
|
CA Personal Firewall Unspecified Remote Issue (ZD-00000202)
|
|
65382
Description:
(Description Provided by CVE) : Multiple unspecified vulnerabilities in the CA (1) PSFormX and (2) WebScan ActiveX controls, as distributed on the CA Global Advisor web site until May 2009, allow remote attackers to execute arbitrary code via unknown vectors.
|
2010-06-10
|
CA PSFormX ActiveX Multiple Unspecified Arbitrary Code Execution
|
|
25234
Description:
(Description Provided by CVE) : Unspecified vulnerability in CA Resource Initialization Manager (CAIRIM) 1.x before 20060502, as used in z/OS Common Services and the LMP component in multiple products, allows attackers to violate integrity via a certain "problem state program" that uses SVC to gain access to supervisor state, key 0.
|
2006-05-02
|
CA Resource Initialization Manager (CAIRIM) LMP SVC Invocation Privilege Escalation
|
|
44609
Description:
(Description Provided by CVE) : The eTrust Common Services (Transport) Daemon (eCSqdmn) in CA Secure Content Manager 8.0.28000.511 and earlier allows remote attackers to cause a denial of service (crash or CPU consumption) via a malformed packet to TCP port 1882.
|
2008-04-18
|
CA Secure Content Manager eCSqdmn Crafted TCP Packets Remote DoS
|
|
70840
Description:
CA Secure Content Manager is prone to an overflow condition. The eTrust Common Services Transport service, ECSQdmn.exe, fails to properly sanitize user-supplied input resulting in a heap-based buffer overflow. With a specially crafted request to port 1882, a remote attacker can potentially execute arbitrary code.
|
2011-02-08
|
CA Secure Content Manager ECSQdmn.exe DWORD Overflow
|
|
46013
Description:
(Description Provided by CVE) : Multiple stack-based buffer overflows in the HTTP Gateway Service (icihttp.exe) in CA eTrust Secure Content Manager 8.0 allow remote attackers to execute arbitrary code or cause a denial of service via long FTP responses, related to (1) the file month field in a LIST command; (2) the PASV command; and (3) directories, files, and links in a LIST command.
|
2008-06-04
|
CA Secure Content Manager HTTP Gateway Service (icihttp.exe) LIST Command Response Handling Overflow
|
|
46012
Description:
(Description Provided by CVE) : Multiple stack-based buffer overflows in the HTTP Gateway Service (icihttp.exe) in CA eTrust Secure Content Manager 8.0 allow remote attackers to execute arbitrary code or cause a denial of service via long FTP responses, related to (1) the file month field in a LIST command; (2) the PASV command; and (3) directories, files, and links in a LIST command.
|
2008-06-04
|
CA Secure Content Manager HTTP Gateway Service (icihttp.exe) PASV Command Overflow
|
|
62511
Description:
CA Service Desk Tomcat contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'name' parameter upon submission to the 'host-manager/html/add' script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-02-22
|
CA Service Desk Tomcat host-manager/html/add name Parameter XSS
|
|
60848
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in the web interface in CA Service Desk 12.1 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter.
|
2009-12-08
|
CA Service Desk Unspecified XSS
|
|
56969
Description:
(Description Provided by CVE) : CA SiteMinder allows remote attackers to bypass cross-site scripting (XSS) protections for J2EE applications via a request containing non-canonical, "overlong Unicode" in place of blacklisted characters.
|
2009-06-08
|
CA SiteMinder J2EE Application Overlong Unicode XSS Protection Bypass
|
|
56970
Description:
(Description Provided by CVE) : CA SiteMinder allows remote attackers to bypass cross-site scripting (XSS) protections for J2EE applications via a request containing a %00 (encoded null byte).
|
2009-06-08
|
CA SiteMinder J2EE Encoded Null Byte (%00) XSS Protection Bypass
|
|
77570
Description:
CA SiteMinder contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'target' parameter upon submission to the login.fcc script when 'postpreservationdata' is set to fail. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-12-08
|
CA SiteMinder login.fcc target Parameter XSS
|
|
74357
Description:
CA SiteMinder contains a flaw in the Web Agents component that may allow an attacker to gain access to unauthorized privileges. The issue is triggered when parsing multi-line headers, allowing a remote authenticated attacker to gain the privileges of the current user.
|
2011-04-20
|
CA SiteMinder Web Agents Multi-line Header Injection Spoofing Remote Privilege Escalation
|
|
62739
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in WebWorks Help 2.0 through 5.0 in VMware vCenter 4.0 before Update 1 Build 208156; VMware Server 2.0.2; VMware ESX 4.0; VMware Lab Manager 2.x; VMware vCenter Lab Manager 3.x and 4.x before 4.0.1; VMware Stage Manager 1.x before 4.0.1; WebWorks Publisher 6.x through 8.x; WebWorks Publisher 2003; and WebWorks ePublisher 9.0.x through 9.3, 2008.1 through 2008.4, and 2009.x before 2009.3 allow remote attackers to inject arbitrary web script or HTML via (1) wwhelp_entry.html, reachable through index.html and wwhsec.htm, (2) wwhelp/wwhimpl/api.htm, (3) wwhelp/wwhimpl/common/html/frameset.htm, (4) wwhelp/wwhimpl/common/scripts/switch.js, or (5) the window.opener component in wwhelp/wwhimpl/common/html/bookmark.htm, related to (a) unspecified parameters and (b) messages used in topic links for the bookmarking functionality.
|
2010-03-04
|
CA SiteMinder WebWorks Help wwhelp/wwhimpl/api.htm Unspecified Parameter XSS
|
|
62742
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in WebWorks Help 2.0 through 5.0 in VMware vCenter 4.0 before Update 1 Build 208156; VMware Server 2.0.2; VMware ESX 4.0; VMware Lab Manager 2.x; VMware vCenter Lab Manager 3.x and 4.x before 4.0.1; VMware Stage Manager 1.x before 4.0.1; WebWorks Publisher 6.x through 8.x; WebWorks Publisher 2003; and WebWorks ePublisher 9.0.x through 9.3, 2008.1 through 2008.4, and 2009.x before 2009.3 allow remote attackers to inject arbitrary web script or HTML via (1) wwhelp_entry.html, reachable through index.html and wwhsec.htm, (2) wwhelp/wwhimpl/api.htm, (3) wwhelp/wwhimpl/common/html/frameset.htm, (4) wwhelp/wwhimpl/common/scripts/switch.js, or (5) the window.opener component in wwhelp/wwhimpl/common/html/bookmark.htm, related to (a) unspecified parameters and (b) messages used in topic links for the bookmarking functionality.
|
2010-03-04
|
CA SiteMinder WebWorks Help wwhelp/wwhimpl/common/html/bookmark.htm Unspecified Parameter XSS
|
|
62740
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in WebWorks Help 2.0 through 5.0 in VMware vCenter 4.0 before Update 1 Build 208156; VMware Server 2.0.2; VMware ESX 4.0; VMware Lab Manager 2.x; VMware vCenter Lab Manager 3.x and 4.x before 4.0.1; VMware Stage Manager 1.x before 4.0.1; WebWorks Publisher 6.x through 8.x; WebWorks Publisher 2003; and WebWorks ePublisher 9.0.x through 9.3, 2008.1 through 2008.4, and 2009.x before 2009.3 allow remote attackers to inject arbitrary web script or HTML via (1) wwhelp_entry.html, reachable through index.html and wwhsec.htm, (2) wwhelp/wwhimpl/api.htm, (3) wwhelp/wwhimpl/common/html/frameset.htm, (4) wwhelp/wwhimpl/common/scripts/switch.js, or (5) the window.opener component in wwhelp/wwhimpl/common/html/bookmark.htm, related to (a) unspecified parameters and (b) messages used in topic links for the bookmarking functionality.
|
2010-03-04
|
CA SiteMinder WebWorks Help wwhelp/wwhimpl/common/html/frameset.htm Unspecified Parameter XSS
|
|
62741
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in WebWorks Help 2.0 through 5.0 in VMware vCenter 4.0 before Update 1 Build 208156; VMware Server 2.0.2; VMware ESX 4.0; VMware Lab Manager 2.x; VMware vCenter Lab Manager 3.x and 4.x before 4.0.1; VMware Stage Manager 1.x before 4.0.1; WebWorks Publisher 6.x through 8.x; WebWorks Publisher 2003; and WebWorks ePublisher 9.0.x through 9.3, 2008.1 through 2008.4, and 2009.x before 2009.3 allow remote attackers to inject arbitrary web script or HTML via (1) wwhelp_entry.html, reachable through index.html and wwhsec.htm, (2) wwhelp/wwhimpl/api.htm, (3) wwhelp/wwhimpl/common/html/frameset.htm, (4) wwhelp/wwhimpl/common/scripts/switch.js, or (5) the window.opener component in wwhelp/wwhimpl/common/html/bookmark.htm, related to (a) unspecified parameters and (b) messages used in topic links for the bookmarking functionality.
|
2010-03-04
|
CA SiteMinder WebWorks Help wwhelp/wwhimpl/common/scripts/switch.js Unspecified Parameter XSS
|
|
62738
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in WebWorks Help 2.0 through 5.0 in VMware vCenter 4.0 before Update 1 Build 208156; VMware Server 2.0.2; VMware ESX 4.0; VMware Lab Manager 2.x; VMware vCenter Lab Manager 3.x and 4.x before 4.0.1; VMware Stage Manager 1.x before 4.0.1; WebWorks Publisher 6.x through 8.x; WebWorks Publisher 2003; and WebWorks ePublisher 9.0.x through 9.3, 2008.1 through 2008.4, and 2009.x before 2009.3 allow remote attackers to inject arbitrary web script or HTML via (1) wwhelp_entry.html, reachable through index.html and wwhsec.htm, (2) wwhelp/wwhimpl/api.htm, (3) wwhelp/wwhimpl/common/html/frameset.htm, (4) wwhelp/wwhimpl/common/scripts/switch.js, or (5) the window.opener component in wwhelp/wwhimpl/common/html/bookmark.htm, related to (a) unspecified parameters and (b) messages used in topic links for the bookmarking functionality.
|
2010-03-04
|
CA SiteMinder WebWorks Help wwhelp_entry.html Unspecified Parameter XSS
|
|
74970
Description:
(Description Provided by CVE) : Directory traversal vulnerability in the Heartbeat Web Service in CA.Itm.Server.ManagementWS.dll in the Management Server in CA Total Defense (TD) r12 before SE2 allows remote attackers to execute arbitrary code via directory traversal sequences in the GUID parameter in an upload request to FileUploadHandler.ashx.
|
2011-04-13
|
CA Total Defense Heartbeat Web Service FileUploadHandler.ashx GUID Parameter Traversal Arbitrary File Upload
|
|
74969
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in the Unified Network Control (UNC) Server in CA Total Defense (TD) r12 before SE2 allow remote attackers to execute arbitrary SQL commands via vectors involving the (1) UnAssignFunctionalRoles, (2) UnassignAdminRoles, (3) DeleteFilter, (4) NonAssignedUserList, (5) DeleteReportLayout, (6) DeleteReports, and (7) RegenerateReport stored procedures.
|
2011-04-13
|
CA Total Defense MainApplication.html DeleteFilter Stored Procedure SQL Injection
|
|
74968
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in the Unified Network Control (UNC) Server in CA Total Defense (TD) r12 before SE2 allow remote attackers to execute arbitrary SQL commands via vectors involving the (1) UnAssignFunctionalRoles, (2) UnassignAdminRoles, (3) DeleteFilter, (4) NonAssignedUserList, (5) DeleteReportLayout, (6) DeleteReports, and (7) RegenerateReport stored procedures.
|
2011-04-13
|
CA Total Defense management.asmx Multiple Stored Procedure SQL Injection
|
|
78931
Description:
CA Total Defense contains a flaw that may lead to an unauthorized information disclosure. The issue is due to the App_Code.dll library within the UNC management web service, which will disclose encrypted unsalted domain credentials to a remote attacker.
|
2012-02-09
|
CA Total Defense Suite UNC Management Web Service App_Code.dll Domain Credentials Disclosure
|
|
78930
Description:
CA Total Defense contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the management.asmx script not properly sanitizing user-supplied input of SOAP requests before being used in a SQL query for the ExportReport and uncsp_ViewReportsHomepage stored procedures. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-02-09
|
CA Total Defense Suite UNC management.asmx Multiple Stored Procedure SQL Injection
|
|
74967
Description:
(Description Provided by CVE) : The management.asmx module in the Management Web Service in the Unified Network Control (UNC) Server in CA Total Defense (TD) r12 before SE2 sends a cleartext response to unspecified getDBConfigSettings requests, which makes it easier for remote attackers to obtain database credentials, and subsequently execute arbitrary code, by sniffing the network, related to the UNCWS Web Service.
|
2011-04-13
|
CA Total Defense Web Management Service management.asmx Module getDBConfigSettings() Method Remote Server Database Credentials Disclosure
|
|
3277
Description:
CA Unicenter contains a flaw that allows a local user to execute arbitrary commands with root privileges. The issue is due to a flaw in the "acctotal" program which insecurely calls the "acctotal.sh" shell script. Due to improper sanity checking of the CAIGLBL0000 variable, a user can subvert the path and script called by CA Unicenter.
|
1995-07-01
|
CA Unicenter acctotal Execute Arbitrary Commands
|
|
14310
Description:
(Description Provided by CVE) : Computer Associates (CA) Unicenter Asset Management (UAM) 4.0 does not properly initialize the "Change Credentials for Database" window, which allows local users to recover the SQL Admin password via certain methods.
|
2005-02-14
|
CA Unicenter Asset Management Admin Console Masked SQL Password Disclosure
|
|
14312
Description:
(Description Provided by CVE) : SQL injection vulnerability in the Query Designer for Computer Associates (CA) Unicenter Asset Management (UAM) 4.0 allows remote attackers to execute arbitrary SQL via an imported file.
|
2005-02-14
|
CA Unicenter Asset Management Query Designer Import SQL Injection
|
|
14311
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in the Reporter for Computer Associates (CA) Unicenter Asset Management (UAM) 4.0 allows remote attackers to inject arbitrary HTML or web script via the (1) name or (2) description in a report template.
|
2005-02-14
|
CA Unicenter Asset Management Reporter Multiple Field XSS
|
|
3242
Description:
Unicenter Asset Manager uses a weak encryption algorithm to store passwords. A local attacker that has access to configuration files could obtain the encrypted passwords and trivially decrypt them.
|
2003-05-20
|
CA Unicenter Asset Management Weak Password Encryption
|