header-logo
Suggest Exploit
vendor:
eTrust Security Command Center
by:
Unknown
7.5
CVSS
HIGH
Information Disclosure, Arbitrary File Deletion, Replay
200, 22, 294
CWE
Product Name: eTrust Security Command Center
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: No
Related CWE: Unknown
CPE: a:ca:etrust_security_command_center:unknown
Metasploit:
Other Scripts:
Platforms Tested:
Unknown

Multiple Vulnerabilities in CA eTrust Security Command Center and eTrust Audit

The vulnerabilities in CA eTrust Security Command Center (eSCC) and eTrust Audit include an information-disclosure issue, an arbitrary-file-deletion issue, and a replay issue. These vulnerabilities are due to the software's failure to validate user input and design errors in handling user permissions and secure data-transmission protocols. An attacker can exploit these vulnerabilities to access sensitive information, delete arbitrary files, and carry out external replay attacks.

Mitigation:

No official mitigation or remediation steps provided.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/20139/info

CA eTrust Security Command Center (eSCC) and eTrust Audit are prone to multiple vulnerabilities, including:

- an information-disclosure issue
- an arbitrary-file-deletion issue
- a replay issue.

These vulnerabilities occur because the software fails to validate user input and because of design errors in the way the software handles user permissions and secure data-transmission protocols.

An attacker may exploit these vulnerabilities to access sensitive information, delete arbitrary files with the permissions of the service account, and carry out external replay attacks.

https://www.example.com:8080/etrust/servlet/ePPIServlet?PIProfile=eAV_Report's&PIName=Generate+Pre-7.1+Report+Data&profile= Threat+Management&node=