Home > Support > Global Security Advisor 

Vulnerability Detail

CA eTrust Security Command Center reveal web server path vulnerability

Date Discovered:
21 Sep 2006

Date Published:
21 Sep 2006

Last Updated:
28 Sep 2006

Threat Assessment

Overall Risk:  Medium
Popularity : Medium
Impact:  Medium
Simplicity:  Medium

Characteristics

Vulnerability ID:  34616
Discovered By:  Patrick Webster

Exploitable Locally:  No
Exploitable Remotely:  Yes

Impact:  A remote attacker can reveal web server path.

Root Cause:  Software Vulnerability

 

Description

CA eTrust Security Command Center contains a vulnerability that can allow a remote attacker to discover the web server path on Windows platforms. The vulnerability is due to improper processing of PIProfile function when single quote character sent to ePPIServlet script. An attacker can exploit this vulnerability to reveal web server path.

Back to top

Recommendations



-------------------------------------------------------------------------------
For: CA eTrust Security Command Center r8 SP1 CR1

Please download and install the following patch:



http://supportconnect.ca.com/sc/solcenter/solresults.jsp?aparno=QO81862&startsearch=1

-------------------------------------------------------------------------------
For: CA eTrust Security Command Center r8 SP1 CR2

Please download and install the following patch:



http://supportconnect.ca.com/sc/solcenter/solresults.jsp?aparno=QO81863&startsearch=1

-------------------------------------------------------------------------------
For: CA eTrust Security Command Center 1.0

Please download and install the following patches:



http://supportconnect.ca.com/sc/solcenter/solresults.jsp?aparno=QO81875&startsearch=1

-------------------------------------------------------------------------------
For: CA eTrust Security Command Center - Server r8

Please download and install the following patch:



http://supportconnect.ca.com/sc/solcenter/solresults.jsp?aparno=QO81758&startsearch=1

Back to top

Affected Technologies

Computer Associates: CA eTrust Security Command Center - Server r8
Computer Associates: CA eTrust Security Command Center r8 SP1 CR1
Computer Associates: CA eTrust Security Command Center r8 SP1 CR2
Computer Associates: eTrust Security Command Center 1.0

Back to top

References

Computer Associates: eTrustSCCVuln
Mitre CVE: CVE-2006-4899

Back to top

CA Global Security Advisor

Current threat condition: Low
Low
Find Threats
Viruses Spyware
Vulnerabilities All
 
 
Page Tools