CVE-2011-1654: Path Traversal
Directory traversal vulnerability in the Heartbeat Web Service in CA.Itm.Server.ManagementWS.dll in the Management Server in CA Total Defense (TD) r12 before SE2 allows remote attackers to execute arbitrary code via directory traversal sequences in the GUID parameter in an upload request to FileUploadHandler.ashx.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1654?
CVE-2011-1654 is considered a critical vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2011-1654?
To fix CVE-2011-1654, it is recommended to apply the latest patches or updates provided by Broadcom for CA Total Defense r12.
Who is affected by CVE-2011-1654?
CVE-2011-1654 affects users of CA Total Defense r12 before SE2, particularly those using the Heartbeat Web Service.
What type of attack can exploit CVE-2011-1654?
CVE-2011-1654 can be exploited through directory traversal attacks to execute arbitrary code on the affected server.
What software is impacted by CVE-2011-1654?
CVE-2011-1654 impacts the CA.Total_Defense software version r12, specifically the ManagementWS.dll component.