OSVDB ID: 29009

Title: CA eSCC / eTrust Audit Web Server Path Disclosure

Info

Disclosure

Sep 20, 2006

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

CA eTrust Security Command Center contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker sends a single quote to the 'PIProfile' of the 'ePPIServlet' script, which will disclose the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.

Classification

Location: Remote / Network Access
Attack Type: Information Disclosure
Impact: Loss of Confidentiality
Solution: Patch / RCS
Exploit: Exploit Public
Disclosure: OSVDB Verified, Vendor Verified
OSVDB: Security Software

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, CA has released a patch to address this vulnerability.

Products

Computer Associates

Security Command Center

1.0
r8
r8 SP1 CR1
r8 SP1 CR2

References

Credit

  • Patrick Webster - patrickaushack.com - aushack


Direct URL: http://osvdb.org/29009