CA Products DSM "gui_cm_ctrls" ActiveX Vulnerability
RISK: Medium Risk
A vulnerability has been identified in various CA products, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system. This issue is caused by input validation errors in the DSM "gui_cm_ctrls" ActiveX control when handling user-supplied arguments, which could be exploited by remote attackers to execute arbitrary code by tricking a user into visiting a specially crafted web page.
Impact
- Denial of Service
- Remote Code Execution
System / Technologies affected
- CA BrightStor ARCServe Backup for Laptops and Desktops r11.5
- CA Desktop Management Suite r11.2 C2
- CA Desktop Management Suite r11.2 C1
- CA Desktop Management Suite r11.2a
- CA Desktop Management Suite r11.2
- CA Desktop Management Suite r11.1 (GA, a, C1)
- CA Unicenter Desktop Management Bundle r11.2 C2
- CA Unicenter Desktop Management Bundle r11.2 C1
- CA Unicenter Desktop Management Bundle r11.2a
- CA Unicenter Desktop Management Bundle r11.2
- CA Unicenter Desktop Management Bundle r11.1 (GA, a, C1)
- CA Unicenter Asset Management r11.2 C2
- CA Unicenter Asset Management r11.2 C1
- CA Unicenter Asset Management r11.2a
- CA Unicenter Asset Management r11.2
- CA Unicenter Asset Management r11.1 (GA, a, C1)
- CA Unicenter Software Delivery r11.2 C2
- CA Unicenter Software Delivery r11.2 C1
- CA Unicenter Software Delivery r11.2a
- CA Unicenter Software Delivery r11.2
- CA Unicenter Software Delivery r11.1 (GA, a, C1)
- CA Unicenter Remote Control r11.2 C2
- CA Unicenter Remote Control r11.2 C1
- CA Unicenter Remote Control r11.2a
- CA Unicenter Remote Control r11.2
- CA Unicenter Remote Control r11.1 (GA, a, C1)
- CA Desktop and Server Management r11.2 C2
- CA Desktop and Server Management r11.2 C1
- CA Desktop and Server Management r11.2a
- CA Desktop and Server Management r11.2
- CA Desktop and Server Management r11.1 (GA, a, C1)OpenOffice.org versions prior to 2.4
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
Vulnerability Identifier
Source
Related Link
Share with