Secunia Logo  


Secunia PSI WorldMap
 
CA Service Desk Web Forms Multiple Cross-Site Scripting Vulnerabilities
Secunia Advisory: SA32038
Release Date: 2008-09-26
Last Update: 2008-09-30
Popularity: 2,291 views

Critical:
Less critical
Impact: Cross Site Scripting
Where: From remote
Solution Status: Vendor Patch

Software:CA CMDB 11.x
CA Unicenter Service Desk 11.x

Secunia CVSS-2 Score: Available in Secunia business solutions

Subscribe: Instant alerts on relevant vulnerabilities


Advisory Content (Page 2 of 3)[ 1 ] [ 2 ] [ 3 ]

Solution:
-- CA Service Desk --

Update to version r11.2 and apply patches.

Windows:

CA Service Desk Crystal Report component: QO99896
CA Service Desk Dashboard component: QO99895
CA Service Desk Web Screen Painter component: QO99894
CA Service Desk Web Server component: QO99893
CA Service Desk Server component: QO99892

AIX:

CA Service Desk Web Screen Painter component: QO99905
CA Service Desk Web Server component: QO99901
CA Service Desk Server component: QO99897

HPUX:

CA Service Desk Web Screen Painter component: QO99906
CA Service Desk Web Server component: QO99902
CA Service Desk Server component: QO99898

Linux:

CA Service Desk Web Screen Painter component: QO99907
CA Service Desk Web Server component: QO99903
CA Service Desk Server component: QO99899

Solaris:

CA Service Desk Web Screen Painter component: QO99908
CA Service Desk Web Server component: QO99904
CA Service Desk Server component: QO99900

-- CA CMDB --

Update to CMDB 11.2.

Provided and/or discovered by:
The vendor credits the Open Security Foundation.

Changelog:
2008-09-30: Updated credits section. Updated "Solution" section to reflect that CA CMDB 11.2 already includes the patches and removed CMDB 11.2 from list of affected versions in "Description".

Original Advisory:
CA:
https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=186585

Change Page:
[ 1 ] [ 2 ] [ 3 ]



Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Internet Explorer Charset Inheritance Cross-Site Scripting Vulnerability // 81 views
2. Sun Java JDK / JRE Multiple Vulnerabilities // 81 views
3. Apple Mac OS X Security Update Fixes Multiple Vulnerabilities // 52 views
4. Google Chrome Two Vulnerabilities // 51 views
5. Adobe Flash Player Multiple Vulnerabilities // 47 views
6. Microsoft Windows License Logging Server Buffer Overflow // 47 views
7. Microsoft Windows Active Directory Denial of Service // 44 views
8. Red Hat update for java-1.6.0-sun // 44 views
9. Oracle Document Capture EasyMail ActiveX Control Vulnerabilities // 40 views
10. Mozilla Firefox Multiple Vulnerabilities // 39 views