HIGH · 7.5

CVE-2006-6641

Unspecified vulnerability in CA CleverPath Portal before maintenance version 4.71.001_179_060830, as used in multiple products including BrightStor Portal r11.1, CleverPath Aion BPM r10 through r10.2,...

Vulnerability Description

Unspecified vulnerability in CA CleverPath Portal before maintenance version 4.71.001_179_060830, as used in multiple products including BrightStor Portal r11.1, CleverPath Aion BPM r10 through r10.2, eTrust Security Command Center r1 and r8, and Unicenter, does not properly handle when multiple Portal servers are started at the same time and share the same data store, which might cause a Portal user to inherit the session and credentials of a user who is on another Portal server.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
ArcserveBrightstor11.1
BroadcomCleverpath Portal<= 4.71
CleverpathAion Bpmr10
CleverpathPortalr4.7
EtrustSecurity Command Centerr1
UnicenterAsset And Portfolio Managementr11
UnicenterDatabase Command Centerr11.1
UnicenterDatabase Management Portalr11
UnicenterEnterprise Job Managerr1_sp3
UnicenterManagement Portalr2.0
UnicenterWorkload Control Centerr1_sp4

References

FAQ

What is CVE-2006-6641?

CVE-2006-6641 is a vulnerability with a CVSS score of 7.5 (HIGH). Unspecified vulnerability in CA CleverPath Portal before maintenance version 4.71.001_179_060830, as used in multiple products including BrightStor Portal r11.1, CleverPath Aion BPM r10 through r10.2,...

How severe is CVE-2006-6641?

CVE-2006-6641 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2006-6641?

Check the references section above for vendor advisories and patch information. Affected products include: Arcserve Brightstor, Broadcom Cleverpath Portal, Cleverpath Aion Bpm, Cleverpath Portal, Etrust Security Command Center.