Home→Descriptions→SA51429
| Secunia ID | |
| CVE-ID | |
| Release Date |
06 Dec 2012 |
| Criticality | |
| Solution Status |
Vendor Patch |
| Software |
CA XCOM Data Transport r11 |
| Where | |
| Impact |
System accessThis covers vulnerabilities where malicious people are able to gain system access and execute arbitrary code with the privileges of a local user. |
| Description |
A vulnerability has been reported in CA XCOM Data Transport, which can be exploited by malicious people to compromise a vulnerable system. The vulnerability is caused due to the application not properly verifying certain requests and can be exploited to execute arbitrary commands. Successful exploitation may allow execution of arbitrary code. The vulnerability is reported in versions 11.0 and 11.5. |
| Solution |
Apply patch (please see the vendor's advisory for details). |
| Reported by |
The vendor credits Jurgens van der Merwe and Junaid Loonat, SensePost. |
| Original Advisory |
CA20121205-01: |