PT-2006-7243 · Ca · Ca Brightstor Portal+4
Published
2006-12-20
·
Updated
2021-04-07
·
CVE-2006-6641
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
CA CleverPath Portal versions prior to 4.71.001 179 060830
CA BrightStor Portal version r11.1
CA CleverPath Aion BPM versions prior to r10.3
CA eTrust Security Command Center versions r1 and r8
CA Unicenter (affected versions not specified)
Description
The issue arises when multiple Portal servers are started simultaneously and share the same data store, potentially causing a Portal user to inherit the session and credentials of a user on another Portal server. This could lead to unauthorized access.
Recommendations
For CA CleverPath Portal versions prior to 4.71.001 179 060830, update to version 4.71.001 179 060830 or later.
For CA BrightStor Portal version r11.1, consider upgrading to a version that incorporates the fix for CA CleverPath Portal.
For CA CleverPath Aion BPM versions prior to r10.3, update to version r10.3 or later.
For CA eTrust Security Command Center versions r1 and r8, apply the necessary patches or updates to address the issue.
For CA Unicenter, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ca Brightstor Portal
Ca Cleverpath Aion Bpm
Ca Cleverpath Portal
Ca Unicenter
Ca Etrust Security Command Center