MEDIUM · 6.4

CVE-2006-4901

Computer Associates (CA) eTrust Security Command Center 1.0 and r8 up to SP1 CR2, and eTrust Audit 1.5 and r8, allows remote attackers to spoof alerts and conduct replay attacks by invoking eTSAPISend...

Vulnerability Description

Computer Associates (CA) eTrust Security Command Center 1.0 and r8 up to SP1 CR2, and eTrust Audit 1.5 and r8, allows remote attackers to spoof alerts and conduct replay attacks by invoking eTSAPISend.exe with the desired arguments.

CVSS Score

6.4

MEDIUM

AV:N/AC:L/Au:N/C:N/I:P/A:P
Confidentiality
NONE
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
BroadcomEtrust Audit Client1.5
BroadcomEtrust Audit Datatools1.5
BroadcomEtrust Audit Policy Manager1.5
BroadcomEtrust Security Command Center1.0

References

FAQ

What is CVE-2006-4901?

CVE-2006-4901 is a vulnerability with a CVSS score of 6.4 (MEDIUM). Computer Associates (CA) eTrust Security Command Center 1.0 and r8 up to SP1 CR2, and eTrust Audit 1.5 and r8, allows remote attackers to spoof alerts and conduct replay attacks by invoking eTSAPISend...

How severe is CVE-2006-4901?

CVE-2006-4901 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2006-4901?

Check the references section above for vendor advisories and patch information. Affected products include: Broadcom Etrust Audit Client, Broadcom Etrust Audit Datatools, Broadcom Etrust Audit Policy Manager, Broadcom Etrust Security Command Center.