Computer Associates Service Desk Cross-Site Scripting Vulnerability
BID:37253
Info
Computer Associates Service Desk Cross-Site Scripting Vulnerability
| Bugtraq ID: | 37253 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-4149 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 08 2009 12:00AM |
| Updated: | Dec 08 2009 09:04PM |
| Credit: | Anonymous |
| Vulnerable: |
Computer Associates Service Desk 12.1 |
| Not Vulnerable: | |
Discussion
Computer Associates Service Desk Cross-Site Scripting Vulnerability
Computer Associates Service Desk is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Service Desk 12.1 is vulnerable; other versions may also be affected.
Computer Associates Service Desk is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Service Desk 12.1 is vulnerable; other versions may also be affected.
Exploit / POC
Computer Associates Service Desk Cross-Site Scripting Vulnerability
Attackers can exploit this issue by enticing an unsuspecting to victim to follow a malicious URI.
Attackers can exploit this issue by enticing an unsuspecting to victim to follow a malicious URI.
Solution / Fix
Computer Associates Service Desk Cross-Site Scripting Vulnerability
Solution:
Updates are available. Please see the references for details.
Computer Associates Service Desk 12.1
Solution:
Updates are available. Please see the references for details.
Computer Associates Service Desk 12.1
-
Computer Associates RO12848
Windows
https://support.ca.com/irj/portal/anonymous/redirArticles?reqPage=sear ch&searchID=RO12848 -
Computer Associates RO12851
AIX
https://support.ca.com/irj/portal/anonymous/redirArticles?reqPage=sear ch&searchID=RO12851 -
Computer Associates RO12853
HP
https://support.ca.com/irj/portal/anonymous/redirArticles?reqPage=sear ch&searchID=RO12853 -
Computer Associates RO12855
Linux
https://support.ca.com/irj/portal/anonymous/redirArticles?reqPage=sear ch&searchID=RO12855 -
Computer Associates RO12857
Sun
https://support.ca.com/irj/portal/anonymous/redirArticles?reqPage=sear ch&searchID=RO12857
References
Computer Associates Service Desk Cross-Site Scripting Vulnerability
References:
References:
- CA Service Desk Homepage (Computer Associates)
- CA20091208-01 : Security Notice for CA Service Desk (Computer Associates)