Computer Associates Multiple CleverPath Portal Environments Session Hijacking Vulnerability
BID:21681
Info
Computer Associates Multiple CleverPath Portal Environments Session Hijacking Vulnerability
| Bugtraq ID: | 21681 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 20 2006 12:00AM |
| Updated: | Dec 22 2006 12:03AM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
Computer Associates Unicenter Workload Control Center 1.0 SP4 Computer Associates Unicenter Management Portal 3.1 Computer Associates Unicenter Management Portal 2.0 Computer Associates Unicenter Management Portal 11.0 Computer Associates Unicenter Enterprise Job Manager 1.0 SP3 Computer Associates Unicenter Database Management Portal 11 Computer Associates Unicenter Database Command Center 11.1 Computer Associates Unicenter Asset Portfolio Management 11.0 Computer Associates eTrust Security Command Center r8 Computer Associates eTrust Security Command Center 1.0 Computer Associates CleverPath Portal 4.7 Computer Associates CleverPath Portal 4.71 Computer Associates CleverPath Portal 4.51 Computer Associates CleverPath Aion BPM 10.2 Computer Associates CleverPath Aion BPM 10.1 Computer Associates CleverPath Aion BPM 10 Computer Associates BrightStor Portal 11.1 |
| Not Vulnerable: | |
Discussion
Computer Associates Multiple CleverPath Portal Environments Session Hijacking Vulnerability
Computer Associates multiple CleverPath Portal environments are prone to a session-hijacking vulnerability.
The vulnerability affects only multiserver CleverPath Portal environments, which is not the default deployment.
An attacker can exploit this issue to hijack the portal session and associated security authentication of a user running on another portal server.
This issue affects the CleverPath Portal solution and other products that embed this portal technology.
Computer Associates multiple CleverPath Portal environments are prone to a session-hijacking vulnerability.
The vulnerability affects only multiserver CleverPath Portal environments, which is not the default deployment.
An attacker can exploit this issue to hijack the portal session and associated security authentication of a user running on another portal server.
This issue affects the CleverPath Portal solution and other products that embed this portal technology.
Exploit / POC
Computer Associates Multiple CleverPath Portal Environments Session Hijacking Vulnerability
Attackers can exploit this issue via a web client.
Attackers can exploit this issue via a web client.
Solution / Fix
Computer Associates Multiple CleverPath Portal Environments Session Hijacking Vulnerability
Solution:
The vendor released an advisory and fixes to address this issue. Please see the references for more information.
Computer Associates CleverPath Aion BPM 10.2
Computer Associates Unicenter Database Command Center 11.1
Computer Associates Unicenter Enterprise Job Manager 1.0 SP3
Computer Associates CleverPath Portal 4.71
Computer Associates Unicenter Database Management Portal 11
Computer Associates CleverPath Aion BPM 10.1
Computer Associates Unicenter Management Portal 11.0
Computer Associates CleverPath Portal 4.51
Computer Associates Unicenter Workload Control Center 1.0 SP4
Computer Associates Unicenter Asset Portfolio Management 11.0
Computer Associates Unicenter Management Portal 2.0
Computer Associates Unicenter Management Portal 3.1
Computer Associates CleverPath Portal 4.7
Solution:
The vendor released an advisory and fixes to address this issue. Please see the references for more information.
Computer Associates CleverPath Aion BPM 10.2
-
Computer Associates 4.71.001_180_060928_full.zip
ftp://ftp.ca.com/pub/portal/4.71/4.71.001_180_060928/4.71.001_180_0609 28_full.zip
Computer Associates Unicenter Database Command Center 11.1
-
Computer Associates 4.7.001_143_061031_full.zip
ftp://ftp.ca.com/pub/portal/4.7/4.7.001_143_061031/4.7.001_143_061031_ full.zip
Computer Associates Unicenter Enterprise Job Manager 1.0 SP3
-
Computer Associates 4.51.007_178_061023_full.zip
ftp://ftp.ca.com/pub/portal/4.51/4.51.007/4.51.007_178_061023/4.51.007 _178_061023_full.zip
Computer Associates CleverPath Portal 4.71
-
Computer Associates 4.71.001_180_060928_full.zip
ftp://ftp.ca.com/pub/portal/4.71/4.71.001_180_060928/4.71.001_180_0609 28_full.zip
Computer Associates Unicenter Database Management Portal 11
-
Computer Associates 4.51.007_178_061023_full.zip
ftp://ftp.ca.com/pub/portal/4.51/4.51.007/4.51.007_178_061023/4.51.007 _178_061023_full.zip
Computer Associates CleverPath Aion BPM 10.1
-
Computer Associates 4.7.001_143_061031_full.zip
ftp://ftp.ca.com/pub/portal/4.7/4.7.001_143_061031/4.7.001_143_061031_ full.zip
Computer Associates Unicenter Management Portal 11.0
-
Computer Associates 4.7.001_144_061115_full.zip
ftp://ftp.ca.com/pub/portal/4.7/4.7.001_144_061115/4.7.001_144_061115_ full.zip
Computer Associates CleverPath Portal 4.51
-
Computer Associates 4.51.007_178_061023_full.zip
ftp://ftp.ca.com/pub/portal/4.51/4.51.007/4.51.007_178_061023/4.51.007 _178_061023_full.zip
Computer Associates Unicenter Workload Control Center 1.0 SP4
-
Computer Associates 4.71.001_180_060928_full.zip
ftp://ftp.ca.com/pub/portal/4.71/4.71.001_180_060928/4.71.001_180_0609 28_full.zip
Computer Associates Unicenter Asset Portfolio Management 11.0
-
Computer Associates 4.7.001_143_061031_full.zip
ftp://ftp.ca.com/pub/portal/4.7/4.7.001_143_061031/4.7.001_143_061031_ full.zip
Computer Associates Unicenter Management Portal 2.0
-
Computer Associates 3.51.001_20061005_00.zip
ftp://ftp.ca.com/pub/portal/3.51/3.51.001_20061005_00/3.51.001_2006100 5_00.zip
Computer Associates Unicenter Management Portal 3.1
-
Computer Associates 4.51.007_181_061109_full.zip
ftp://ftp.ca.com/pub/portal/4.51/4.51.007/4.51.007_181_061109/4.51.007 _181_061109_full.zip
Computer Associates CleverPath Portal 4.7
-
Computer Associates 4.7.001_143_061031_full.zip
ftp://ftp.ca.com/pub/portal/4.7/4.7.001_143_061031/4.7.001_143_061031_ full.zip
References
Computer Associates Multiple CleverPath Portal Environments Session Hijacking Vulnerability
References:
References:
- Computer Associates Homepage (Computer Associates)
- Security Notice for CA CleverPath and Embedded Portal Customers (Computer Associates)
- CA CleverPath Portal Session Inheritance Vulnerability (Williams, James K)