CA Community






CA20111208-01: Security Notice for CA SiteMinder

Published: December 09 2011, 07:33 AM | 3 Comment(s)
by Ken Williams

Today we published a security notice and fixes to address a medium risk, publicly known vulnerability in CA SiteMinder. The vulnerability, CVE-2011-4054, occurs due to insufficient validation of postpreservationdata parameter input utilized in the login.fcc form. A malicious user can submit a specially crafted request to effectively hijack a victim’s browser. Vulnerability details were first publicized by CERT on 2011-12-07 in US-CERT Vulnerability Note VU#713012 - CA Siteminder login.fcc form xss vulnerability. We are not aware of any active exploitation, and due to the lower risk, we do not anticipate any widespread exploitation. Note that fixes are currently available only for SiteMinder R12. Fixes for SiteMinder R6 should be available in January 2012.

CA20111208-01: Security Notice for CA SiteMinder

https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID={A7DA8AC2-E9B4-4DDE-B828-098E0955A344}

Thanks and regards,
Ken Williams, Director
CA Technologies Product Vulnerability Response Team
CA Technologies Business Unit Operations
wilja22@ca.com

 

The opinions and statements on this site are my own and do not necessarily reflect the opinions or policies of CA Technologies.

Share this post:  EmailEmail

 

By: Ken Williams
Ken Williams is a Director with the CA Vulnerability Research Team. As a veteran vulnerability researcher, Ken has worked as the Director of the CA Vulnerability Research Team and eVM Research Team, Director of Vulnerability Research at eSecurityOnline, Manager of the Vulnerability Research Team at Ernst...
Read More..

CA20111116-01: Security Notice for CA Directory

Published: November 16 2011, 05:41 PM | no comments
by Kevin Kotas

Today, I published a new security notice for CA Directory. The notice addresses a high risk denial of service vulnerability dealing with specially malformed SNMP packets, which was reported to us by nabCERT, National Australia Bank. At this time, we are not aware of any active exploitation. See below for details.

CA20111116-01: Security Notice for CA Directory
https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=%7b286545DB-00B9-4B4C-8DE7-F00827F3CC75%7d

Kevin Kotas
CA Technologies Product Vulnerability Response Team

The opinions and statements on this site are my own and do not necessarily reflect the opinions or policies of CA.

Share this post:  EmailEmail

 

By: Kevin Kotas
Kevin Kotas is an Engineering Services Architect with the CA Product Vulnerability Response Team. He has over eleven years of vulnerability management experience and discovered several vulnerabilities in products from multiple major software providers. Kevin holds a B.S. degree in Computer Science from...
Read More..

CA20110809-01: Security Notice for CA ARCserve D2D

Published: August 12 2011, 03:25 PM | no comments
by Ken Williams

On August 9, 2011, we published a security notice and fix to address a high risk vulnerability in ARCserve D2D r15.  The vulnerability, CVE-2011-3011, is due to improper session handling. A remote attacker can potentially access credentials and execute arbitrary commands.  Vulnerability and exploit details were originally disclosed on BugTraq on July 26, 2011, and CA was not contacted prior to the public disclosure.  We are not aware of any active exploitation at this time, but we do anticipate activity because of the public disclosure of exploit details.

CA20110809-01: Security Notice for CA ARCserve D2D
https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID={7D3ACC0F-6C01-4BE2-B5C0-C430CEB45BE6}

Thanks and regards,
Ken Williams, Director
CA Technologies Product Vulnerability Response Team
CA Technologies Business Unit Operations
wilja22@ca.com

 

The opinions and statements on this site are my own and do not necessarily reflect the opinions or policies of CA.

 

Share this post:  EmailEmail

 

By: Ken Williams
Ken Williams is a Director with the CA Vulnerability Research Team. As a veteran vulnerability researcher, Ken has worked as the Director of the CA Vulnerability Research Team and eVM Research Team, Director of Vulnerability Research at eSecurityOnline, Manager of the Vulnerability Research Team at Ernst...
Read More..

ARCserve D2D public disclosure of vulnerability and exploit details

Published: July 26 2011, 02:30 PM | no comments
by Ken Williams

CA Technologies is aware of ARCserve D2D vulnerability and exploit details that were posted to BugTraq on 2011-07-26.  We're currently reviewing the information and will post an update after we have completed our initial investigation.

Thanks and regards,
Ken Williams, Director
CA Technologies Product Vulnerability Response Team
CA Technologies Business Unit Operations
wilja22@ca.com

 

The opinions and statements on this site are my own and do not necessarily reflect the opinions or policies of CA.

Share this post:  EmailEmail

 

By: Ken Williams
Ken Williams is a Director with the CA Vulnerability Research Team. As a veteran vulnerability researcher, Ken has worked as the Director of the CA Vulnerability Research Team and eVM Research Team, Director of Vulnerability Research at eSecurityOnline, Manager of the Vulnerability Research Team at Ernst...
Read More..

CA20110720-01: Security Notice for CA Gateway Security and Total Defense

Published: July 20 2011, 04:00 PM | no comments
by Kevin Kotas

Today I published a new security notice for a high risk vulnerability reported to us through the TippingPoint ZDI program. The vulnerability is a remote code exeuction in Gateway Security, which is included with Total Defense. At this time we are not aware of any active exploitation.

CA20110720-01: Security Notice for CA Gateway Security and Total Defense
https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID={5E404992-6B58-4C44-A29D-027D05B6285D}

Kevin Kotas
CA Technologies Product Vulnerability Response Team

The opinions and statements on this site are my own and do not necessarily reflect the opinions or policies of CA.

Share this post:  EmailEmail

 

By: Kevin Kotas
Kevin Kotas is an Engineering Services Architect with the CA Product Vulnerability Response Team. He has over eleven years of vulnerability management experience and discovered several vulnerabilities in products from multiple major software providers. Kevin holds a B.S. degree in Computer Science from...
Read More..

More Posts Next page »