7.5

CVE-2006-6641

Unspecified vulnerability in CA CleverPath Portal before maintenance version 4.71.001_179_060830, as used in multiple products including BrightStor Portal r11.1, CleverPath Aion BPM r10 through r10.2, eTrust Security Command Center r1 and r8, and Unicenter, does not properly handle when multiple Portal servers are started at the same time and share the same data store, which might cause a Portal user to inherit the session and credentials of a user who is on another Portal server.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Arcserve ≫ Brightstor Version 11.1
Broadcom ≫ Cleverpath Portal Version <= 4.71
Cleverpath ≫ Aion Bpm Version r10
Cleverpath ≫ Aion Bpm Version r10.1
Cleverpath ≫ Aion Bpm Version r10.2
Cleverpath ≫ Portal Version r4.7
Cleverpath ≫ Portal Version r4.51
Cleverpath ≫ Portal Version r4.71
Unicenter ≫ Enterprise Job Manager Version r1_sp3
Unicenter ≫ Management Portal Version r2.0
Unicenter ≫ Management Portal Version r3.1
Unicenter ≫ Management Portal Version r11.0
Unicenter ≫ Workload Control Center Version r1_sp4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.57% 0.834
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/23426
http://securitytracker.com/id?1017429
http://supportconnectw.ca.com/public/ca_common_docs/cpportal_secnot.asp
Vendor Advisory
http://www.osvdb.org/30854
http://www.securityfocus.com/archive/1/455041/100/0/threaded
http://www.securityfocus.com/bid/21681
http://www.vupen.com/english/advisories/2006/5091
http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=34876