First published: Wed Dec 20 2006(Updated: )
Unspecified vulnerability in CA CleverPath Portal before maintenance version 4.71.001_179_060830, as used in multiple products including BrightStor Portal r11.1, CleverPath Aion BPM r10 through r10.2, eTrust Security Command Center r1 and r8, and Unicenter, does not properly handle when multiple Portal servers are started at the same time and share the same data store, which might cause a Portal user to inherit the session and credentials of a user who is on another Portal server.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CA Unicenter Enterprise Job Manager | =r1_sp3 | |
Broadcom CleverPath AION | =r10.2 | |
Broadcom CleverPath AION | =r10 | |
Broadcom CleverPath Portal | =r4.71 | |
Broadcom CleverPath AION | =r10.1 | |
CA Unicenter Management Portal | =r11 | |
Broadcom Unicenter Management Portal | =r2.0 | |
Broadcom CleverPath Portal | =r4.51 | |
Broadcom Unicenter Management Portal | =r11.0 | |
Broadcom Unicenter Management Portal | =r3.1 | |
Broadcom Unicenter Asset Portfolio Management | =r11 | |
Unicenter Database Command Center | =r11.1 | |
Unicenter Workload Control Center | =r1_sp4 | |
CA BrightStor ARCserve Backup | =11.1 | |
Broadcom eTrust Security Command Center | =r8 | |
Broadcom eTrust Security Command Center | =r1 | |
Broadcom CleverPath Portal | =r4.7 | |
Broadcom CleverPath Portal | <=4.71 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-6641 has not been assigned a specific CVSS score, but it is categorized as a vulnerability that may impact system integrity.
The vulnerability can be mitigated by upgrading to the maintenance version 4.71.001_179_060830 or later of CA CleverPath Portal and related products.
CVE-2006-6641 affects multiple products including CA CleverPath Portal, CA BrightStor ARCserve Backup, and eTrust Security Command Center.
Yes, CVE-2006-6641 could potentially be exploited remotely if an attacker interacts with an affected application.
Exploiting CVE-2006-6641 may allow unauthorized access or manipulation of the affected systems.