Vulnerability CVE-2005-2669


Published: 2005-08-23   Modified: 2012-02-12

Description:
Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allows remote attackers to execute arbitrary commands via spoofed CAFT packets.

Type:

CWE-Other

CVSS2 => (AV:N/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
10/10
10/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
CA -> Unicenter management 
CA -> Unicenter management portal 
CA -> Advantage data transport 
CA -> Unicenter network and systems management 
CA -> Adviseit 
CA -> Unicenter nsm wireless network management option 
CA -> Brightstor portal 
CA -> Unicenter performance management 
CA -> Brightstor san manager 
CA -> Unicenter remote control 
CA -> Cleverpath aion 
CA -> Unicenter service level management 
CA -> Cleverpath ecm 
CA -> Unicenter software delivery 
CA -> Cleverpath olap 
CA -> Unicenter tng 
CA -> Cleverpath predictive analysis server 
CA -> Etrust admin 
CA -> Messaging 
CA -> Unicenter application performance monitor 
CA -> Unicenter asset management 
CA -> Unicenter data transport option 
CA -> Unicenter enterprise job manager 
CA -> Unicenter jasmine 

 References:
http://supportconnectw.ca.com/public/ca_common_docs/camsecurity_notice.asp
http://www.securityfocus.com/bid/14623
http://www.vupen.com/english/advisories/2005/1482
http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=32919

Copyright 2024, cxsecurity.com

 

Back to Top