Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2006-6641

Опубликовано: 20 дек. 2006
Источник: nvd
CVSS2: 7.5
EPSS Низкий

Описание

Unspecified vulnerability in CA CleverPath Portal before maintenance version 4.71.001_179_060830, as used in multiple products including BrightStor Portal r11.1, CleverPath Aion BPM r10 through r10.2, eTrust Security Command Center r1 and r8, and Unicenter, does not properly handle when multiple Portal servers are started at the same time and share the same data store, which might cause a Portal user to inherit the session and credentials of a user who is on another Portal server.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:arcserve:brightstor:11.1:*:*:*:*:*:*:*
cpe:2.3:a:broadcom:cleverpath_portal:*:*:*:*:*:*:*:*
Версия до 4.71 (включая)
cpe:2.3:a:cleverpath:aion_bpm:r10:*:*:*:*:*:*:*
cpe:2.3:a:cleverpath:aion_bpm:r10.1:*:*:*:*:*:*:*
cpe:2.3:a:cleverpath:aion_bpm:r10.2:*:*:*:*:*:*:*
cpe:2.3:a:cleverpath:portal:r4.7:*:*:*:*:*:*:*
cpe:2.3:a:cleverpath:portal:r4.51:*:*:*:*:*:*:*
cpe:2.3:a:cleverpath:portal:r4.71:*:*:*:*:*:*:*
cpe:2.3:a:etrust:security_command_center:r1:*:*:*:*:*:*:*
cpe:2.3:a:etrust:security_command_center:r8:*:*:*:*:*:*:*
cpe:2.3:a:unicenter:asset_and_portfolio_management:r11:*:*:*:*:*:*:*
cpe:2.3:a:unicenter:database_command_center:r11.1:*:*:*:*:*:*:*
cpe:2.3:a:unicenter:database_management_portal:r11:*:*:*:*:*:*:*
cpe:2.3:a:unicenter:enterprise_job_manager:r1_sp3:*:*:*:*:*:*:*
cpe:2.3:a:unicenter:management_portal:r2.0:*:*:*:*:*:*:*
cpe:2.3:a:unicenter:management_portal:r3.1:*:*:*:*:*:*:*
cpe:2.3:a:unicenter:management_portal:r11.0:*:*:*:*:*:*:*
cpe:2.3:a:unicenter:workload_control_center:r1_sp4:*:*:*:*:*:*:*

EPSS

Процентиль: 79%
0.01235
Низкий

7.5 High

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

Unspecified vulnerability in CA CleverPath Portal before maintenance version 4.71.001_179_060830, as used in multiple products including BrightStor Portal r11.1, CleverPath Aion BPM r10 through r10.2, eTrust Security Command Center r1 and r8, and Unicenter, does not properly handle when multiple Portal servers are started at the same time and share the same data store, which might cause a Portal user to inherit the session and credentials of a user who is on another Portal server.

EPSS

Процентиль: 79%
0.01235
Низкий

7.5 High

CVSS2

Дефекты

NVD-CWE-Other