Computer Associates Total Defense Multiple SQL Injection Vulnerabilities
BID:47355
Info
Computer Associates Total Defense Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 47355 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-1653 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 13 2011 12:00AM |
| Updated: | Oct 03 2011 08:00PM |
| Credit: | Andrea Micalizzi aka rgod |
| Vulnerable: | |
| Not Vulnerable: |
Computer Associates Total Defense 12 SE2 |
Discussion
Computer Associates Total Defense Multiple SQL Injection Vulnerabilities
Computer Associates Total Defense is prone to multiple SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database. This may also allow an attacker to execute arbitrary commands through an 'exec()' function call with SYSTEM-level privileges, completely compromising an affected computer.
Total Defense versions prior to 12 SE2 are affected.
Computer Associates Total Defense is prone to multiple SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database. This may also allow an attacker to execute arbitrary commands through an 'exec()' function call with SYSTEM-level privileges, completely compromising an affected computer.
Total Defense versions prior to 12 SE2 are affected.
Exploit / POC
Computer Associates Total Defense Multiple SQL Injection Vulnerabilities
Attackers can use a browser to exploit these issues.
The following Metasploit exploit module is available:
Attackers can use a browser to exploit these issues.
The following Metasploit exploit module is available:
Solution / Fix
Computer Associates Total Defense Multiple SQL Injection Vulnerabilities
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
Computer Associates Total Defense Multiple SQL Injection Vulnerabilities
References:
References:
- CA Total Defense Product page (Computer Associates)
- CA20110413-01: Security Notice for CA Total Defense (Computer Associates)
- ZDI-11-128 CA Total Defense Suite UnassignFunctionalUsers Stored Procedure SQL I (Zero Day Initiative)
- ZDI-11-129 CA Total Defense Suite UnassignAdminRoles Stored Procedure SQL Inject (Zero Day Initiative)
- ZDI-11-130 CA Total Defense Suite UNC Management Console DeleteFilter SQL Inject (Zero Day Initiative)
- ZDI-11-131 CA Total Defense Suite NonAssignedUserList Stored Procedure SQL Injec (Zero Day Initiative)
- ZDI-11-132 CA Total Defense Suite UNC Management Console DeleteReportLayout SQL (Zero Day Initiative)
- ZDI-11-133 CA Total Defense Suite UNC Management Console DeleteReports SQL Injec (Zero Day Initiative)
- ZDI-11-134 CA Total Defense Suite UNC Management Console RegenerateReport SQL In (Zero Day Initiative)