HTTP: CA Total Defense Suite UNCWS Multiple Report Stored Procedure SQL Injection

This signature detects attempts to exploit a known vulnerability in CA Total Defense Suite UNCWS. It is due to insufficient validation of user-supplied input. An attacker can exploit this issue by manipulating the SQL query logic to carry out unauthorized actions on the underlying database.

Extended Description

Computer Associates Total Defense is prone to multiple SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in an SQL query. A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database. This may also allow an attacker to execute arbitrary commands through an 'exec()' function call with SYSTEM-level privileges, completely compromising an affected computer. Total Defense versions prior to 12 SE2 are affected.

Affected Products

Computer_associates total_defense

Short Name
HTTP:SQL:INJ:CA-TOTAL-DEFENSE
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CA CVE-2011-1653 Defense Injection Multiple Procedure Report SQL Stored Suite Total UNCWS bid:47355
Release Date
06/15/2011
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Computer_associates

CVSS Score

10.0

Found a potential security threat?