CVE-2005-3653
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD
Description
Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field.
Affected (49)
Products: Broadcom: Brightstor Arcserve Backup, Brightstor Arcserve Backup Laptops Desktops, Brightstor Portal, Brightstor Process Automation Manager, Brightstor San Manager, Brightstor Storage Resource Manager, Etrust Admin, Etrust Audit Aries, Etrust Audit Irecorder, Etrust Identity Minder, Etrust Integrated Threat Management, Itechnology Igateway, Unicenter Asset Portfolio Management, Unicenter Autosys Jm, Unicenter Service Delivery, Unicenter Service Desk, Unicenter Service Desk Knowledge Tools, Unicenter Service Fulfillment, Unicenter Service Metric Analysis · Ca: Brightstor Arcserve Backup, Brightstor Enterprise Backup, Etrust Audit Aries, Etrust Directory, Etrust Secure Content Manager, Unicenter Application Performance Monitor, Unicenter Application Server Managment, Unicenter Ca Web Services Distributed Management, Unicenter Exchange Management Console, Unicenter Management, Unicenter Service Catalog Fulfillment Accounting, Unicenter Service Fulfillment, Unicenter Service Level Management, Unicenter Web Server Management, Unicenter Web Services Distributed Management
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11.1 | |
| Version 11.0 | |
| Version 11.1 | |
| Version 11.1 | |
| Version 11.1 | |
| Version 11.1 | |
| Version 8.1 | |
| Version 8.0 | |
| Version 1.5 sp2 | |
| Version 8.0 | |
| Version 8.0 | |
| Up to 4.0.050615 | |
| Version 11.0 | |
| Version 11.0 | |
| Version 11.0 | |
| Version 11.0 | |
| Version 11.0 | |
| Version 2.2 | |
| Version 11.0 | |
| Version 11 | |
| Version 10.0 | |
| Version 1.5 sp2 | |
| Version 8.1_web_components | |
| Version 8.0 | |
| Version 11.0 | |
| Version 11.0 | |
| Version 11.0 | |
| Version 11.0 | |
| Version 11.0 | |
| Version 11.0 | |
| Version 11.0 | |
| Version 11.0 | |
| Version 11.0 | |
| Version 11.0 |
References (26)
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.