Multiple SQL injection vulnerabilities in Computer Associates (CA) BrightStor Hierarchical Storage Manager (HSM) before r11.6 allow remote attackers to execute arbitrary SQL commands via CsAgent service commands with opcodes (1) 0x07, (2) 0x08, (3) 0x09, (4) 0x1E, (5) 0x32, (6) 0x36, (7) 0x40, and possibly others.
References
Configurations
History
21 Nov 2024, 00:37
Type | Values Removed | Values Added |
---|---|---|
References | () http://dvlabs.tippingpoint.com/advisory/TPTI-07-17 - | |
References | () http://secunia.com/advisories/26914 - Vendor Advisory | |
References | () http://securitytracker.com/id?1018747 - | |
References | () http://supportconnectw.ca.com/public/bstorhsm/infodocs/bstorhsm-secnot.asp - Patch | |
References | () http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=35692 - Patch | |
References | () http://www.securityfocus.com/archive/1/480808/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/25823 - | |
References | () http://www.vupen.com/english/advisories/2007/3275 - Vendor Advisory | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/36828 - |
Information
Published : 2007-10-01 20:17
Updated : 2024-11-21 00:37
NVD link : CVE-2007-5084
Mitre link : CVE-2007-5084
CVE.ORG link : CVE-2007-5084
JSON object : View
Products Affected
broadcom
- brightstor_hierarchical_storage_manager
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')