PT-2006-5653 · Ca · Ca Etrust Security Command Center
Published
2006-09-22
·
Updated
2021-04-09
·
CVE-2006-4900
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
CA eTrust Security Command Center versions 1.0 and r8 up to SP1 CR2
Description
A directory traversal issue allows remote authenticated users to read and delete arbitrary files by using ".." sequences in the
eSCCAdHocHtmlFile parameter to the "eSMPAuditServlet" endpoint. This is due to improper handling by the getadhochtml function.Recommendations
For CA eTrust Security Command Center versions 1.0 and r8 up to SP1 CR2, consider restricting access to the
eSMPAuditServlet endpoint until a proper fix is available. As a temporary workaround, avoid using the eSCCAdHocHtmlFile parameter in the affected endpoint to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ca Etrust Security Command Center