Multiple CA Service Management Products Unspecified Remote Command Execution Vulnerability
BID:33161
Info
Multiple CA Service Management Products Unspecified Remote Command Execution Vulnerability
| Bugtraq ID: | 33161 |
| Class: | Access Validation Error |
| CVE: |
CVE-2009-0043 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 07 2009 12:00AM |
| Updated: | Jan 12 2009 07:02PM |
| Credit: | Michel Arboi of Tenable Network Security |
| Vulnerable: |
Computer Associates Service Metric Analysis 11.1 SP1 Computer Associates Service Metric Analysis 11.1 Computer Associates Service Metric Analysis 11.0 Computer Associates Service Level Management 3.5 |
| Not Vulnerable: | |
Discussion
Multiple CA Service Management Products Unspecified Remote Command Execution Vulnerability
Multiple CA Service Management products are prone to a vulnerability that attackers can leverage to execute arbitrary commands. This issue is the result of insufficient access restrictions.
Successful attacks can compromise the affected application and possibly the underlying computer.
The following applications are vulnerable:
Service Metric Analysis 11.0, 11.1, and 11.1 SP1
Service Level Management 3.5
Multiple CA Service Management products are prone to a vulnerability that attackers can leverage to execute arbitrary commands. This issue is the result of insufficient access restrictions.
Successful attacks can compromise the affected application and possibly the underlying computer.
The following applications are vulnerable:
Service Metric Analysis 11.0, 11.1, and 11.1 SP1
Service Level Management 3.5
Exploit / POC
Multiple CA Service Management Products Unspecified Remote Command Execution Vulnerability
Submitting the following command through netcat or telnet is sufficient to exploit this issue:
[ipconfig /all]
Submitting the following command through netcat or telnet is sufficient to exploit this issue:
[ipconfig /all]
Solution / Fix
Multiple CA Service Management Products Unspecified Remote Command Execution Vulnerability
Solution:
Updates are available; please see the references for more information.
Computer Associates Service Metric Analysis 11.1 SP1
Computer Associates Service Level Management 3.5
Computer Associates Service Metric Analysis 11.1
Computer Associates Service Metric Analysis 11.0
Solution:
Updates are available; please see the references for more information.
Computer Associates Service Metric Analysis 11.1 SP1
-
CA RO04667
https://support.ca.com/irj/portal/anonymous/redirArticles?reqPage=sear ch&searchID=RO04667
Computer Associates Service Level Management 3.5
-
CA RO04649
https://support.ca.com/irj/portal/anonymous/redirArticles?reqPage=sear ch&searchID=RO04649
Computer Associates Service Metric Analysis 11.1
-
CA RO04667
https://support.ca.com/irj/portal/anonymous/redirArticles?reqPage=sear ch&searchID=RO04667
Computer Associates Service Metric Analysis 11.0
References
Multiple CA Service Management Products Unspecified Remote Command Execution Vulnerability
References:
References: