PT-2011-2827 · Ca · Ca Host-Based Intrusion Prevention System+1

Publicado

2011-02-23

·

Atualizado

2018-10-09

·

CVE-2011-1036

CVSS v2.0

8.8

Alta

VetorAV:N/AC:M/Au:N/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions CA Host-Based Intrusion Prevention System (HIPS) versions prior to 8.1.0.88 CA Internet Security Suite (ISS) 2010 versions prior to 1.6.450
Description The issue allows remote attackers to download and execute an arbitrary program onto a client machine. This is achieved through vectors involving the SetXml and Save methods of the XML Security Database Parser class in the HIPSEngine component.
Recommendations For CA Host-Based Intrusion Prevention System (HIPS) versions prior to 8.1.0.88, update to version 8.1.0.88 or later. For CA Internet Security Suite (ISS) 2010 versions prior to 1.6.450, update to version 1.6.450 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2011-1036
ZDI-11-093

Produtos afetados

Ca Host-Based Intrusion Prevention System
Ca Internet Security Suite