CVE-2011-1036: High severity broadcom host-based intrusion prevention system vulnerability
The XML Security Database Parser class in the XMLSecDB ActiveX control in the HIPSEngine component in the Management Server before 8.1.0.88, and the client before 1.6.450, in CA Host-Based Intrusion Prevention System (HIPS) 8.1, as used in CA Internet Security Suite (ISS) 2010, allows remote attackers to download an arbitrary program onto a client machine, and execute this program, via vectors involving the SetXml and Save methods.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1036?
CVE-2011-1036 is classified as a medium severity vulnerability due to its potential impact on remote system security.
How do I fix CVE-2011-1036?
To mitigate CVE-2011-1036, update to CA Host-Based Intrusion Prevention System version 8.1.0.88 or higher.
What types of systems are affected by CVE-2011-1036?
CVE-2011-1036 affects CA Host-Based Intrusion Prevention System version 8.1 and CA Internet Security Suite 2010 and 2011.
What are the potential risks associated with CVE-2011-1036?
The potential risks of CVE-2011-1036 include remote code execution and unauthorized access to sensitive system resources.
Is there a workaround for CVE-2011-1036?
There are no known effective workarounds for CVE-2011-1036 other than applying the recommended software updates.