7.5

CVE-2006-6641

Unspecified vulnerability in CA CleverPath Portal before maintenance version 4.71.001_179_060830, as used in multiple products including BrightStor Portal r11.1, CleverPath Aion BPM r10 through r10.2, eTrust Security Command Center r1 and r8, and Unicenter, does not properly handle when multiple Portal servers are started at the same time and share the same data store, which might cause a Portal user to inherit the session and credentials of a user who is on another Portal server.

Data is provided by the National Vulnerability Database (NVD)
ArcserveBrightstor Version11.1
BroadcomCleverpath Portal Version <= 4.71
CleverpathAion Bpm Versionr10
CleverpathAion Bpm Versionr10.1
CleverpathAion Bpm Versionr10.2
CleverpathPortal Versionr4.7
CleverpathPortal Versionr4.51
CleverpathPortal Versionr4.71
UnicenterEnterprise Job Manager Versionr1_sp3
UnicenterManagement Portal Versionr2.0
UnicenterManagement Portal Versionr3.1
UnicenterManagement Portal Versionr11.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.24% 0.783
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P