<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.ca.com/~d/styles/itemcontent.css"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><title>CA Security Response Blog</title><link>http://community.ca.com/blogs/casecurityresponseblog/default.aspx</link><description /><dc:language>en</dc:language><generator>CommunityServer 2007 SP1 (Build: 20510.895)</generator><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.ca.com/CaSecurityResponseBlog" /><feedburner:info uri="casecurityresponseblog" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><image><link>http://www.ca.com</link><url>http://www.ca.com/images/global/logo_172900.gif</url><title>CA</title></image><feedburner:emailServiceId>CaSecurityResponseBlog</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><item><title>CA20120320-01: Security Notice for CA ARCserve Backup</title><link>http://feeds.ca.com/~r/CaSecurityResponseBlog/~3/euFwHqizZ94/ca20120320-01-security-notice-for-ca-arcserve-backup.aspx</link><pubDate>Tue, 20 Mar 2012 20:49:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:8752</guid><dc:creator>Kevin Kotas</dc:creator><slash:comments>0</slash:comments><comments>http://community.ca.com/blogs/casecurityresponseblog/archive/2012/03/20/ca20120320-01-security-notice-for-ca-arcserve-backup.aspx#comments</comments><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Vulnerability/default.aspx">Vulnerability</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CVE-2012-1662/default.aspx">CVE-2012-1662</category><description>Today I published a new security notice, CA20120320-01, for ARCserve Backup. The notice addresses a medium risk remotely exploitable denial of serivce vulnerability. There are no reports of exploitation in the wild at the time of this post. See below for more information.

CA20120320-01: Security Notice for CA ARCserve...&lt;br/&gt;
&lt;br/&gt;
&amp;nbsp;&lt;img src="http://feeds.feedburner.com/~r/CaSecurityResponseBlog/~4/euFwHqizZ94" height="1" width="1"/&gt;</description><feedburner:origLink>http://community.ca.com/blogs/casecurityresponseblog/archive/2012/03/20/ca20120320-01-security-notice-for-ca-arcserve-backup.aspx</feedburner:origLink></item><item><title>CA20111208-01: Security Notice for CA SiteMinder</title><link>http://feeds.ca.com/~r/CaSecurityResponseBlog/~3/iRqpCTfDMvY/ca20111208-01-security-notice-for-ca-siteminder.aspx</link><pubDate>Fri, 09 Dec 2011 12:33:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:8202</guid><dc:creator>Ken Williams</dc:creator><slash:comments>3</slash:comments><comments>http://community.ca.com/blogs/casecurityresponseblog/archive/2011/12/09/ca20111208-01-security-notice-for-ca-siteminder.aspx#comments</comments><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Vulnerability/default.aspx">Vulnerability</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/SiteMinder/default.aspx">SiteMinder</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CVE-2011-4054/default.aspx">CVE-2011-4054</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CERT/default.aspx">CERT</category><description>Today we published a security notice and fixes to address a medium risk, publicly known vulnerability in CA SiteMinder. The vulnerability, CVE-2011-4054,
occurs due to insufficient validation of postpreservationdata parameter input
utilized in the login.fcc form. A malicious user can submit a specially crafted
request to effectively hijack a victim’s browser. Vulnerability details were first...&lt;br/&gt;
&lt;br/&gt;
&amp;nbsp;&lt;img src="http://feeds.feedburner.com/~r/CaSecurityResponseBlog/~4/iRqpCTfDMvY" height="1" width="1"/&gt;</description><feedburner:origLink>http://community.ca.com/blogs/casecurityresponseblog/archive/2011/12/09/ca20111208-01-security-notice-for-ca-siteminder.aspx</feedburner:origLink></item><item><title>CA20111116-01: Security Notice for CA Directory</title><link>http://feeds.ca.com/~r/CaSecurityResponseBlog/~3/1dYWxWpcY6Q/ca20111116-01-security-notice-for-ca-directory.aspx</link><pubDate>Wed, 16 Nov 2011 22:41:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:8124</guid><dc:creator>Kevin Kotas</dc:creator><slash:comments>0</slash:comments><comments>http://community.ca.com/blogs/casecurityresponseblog/archive/2011/11/16/ca20111116-01-security-notice-for-ca-directory.aspx#comments</comments><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Vulnerability/default.aspx">Vulnerability</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CVE-2011-3849/default.aspx">CVE-2011-3849</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Directory/default.aspx">Directory</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/EEM/default.aspx">EEM</category><description>Today, I published a new security notice for CA Directory. The notice addresses a high risk denial of service vulnerability dealing with specially malformed SNMP packets, which was reported to us by nabCERT, National Australia Bank. At this time, we are not aware of any active exploitation. See below for details.

CA20111116-01: Security Notice for CA...&lt;br/&gt;
&lt;br/&gt;
&amp;nbsp;&lt;img src="http://feeds.feedburner.com/~r/CaSecurityResponseBlog/~4/1dYWxWpcY6Q" height="1" width="1"/&gt;</description><feedburner:origLink>http://community.ca.com/blogs/casecurityresponseblog/archive/2011/11/16/ca20111116-01-security-notice-for-ca-directory.aspx</feedburner:origLink></item><item><title>CA20110809-01: Security Notice for CA ARCserve D2D</title><link>http://feeds.ca.com/~r/CaSecurityResponseBlog/~3/yH6htYqrnxA/ca20110809-01-security-notice-for-ca-arcserve-d2d.aspx</link><pubDate>Fri, 12 Aug 2011 20:25:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:7709</guid><dc:creator>Ken Williams</dc:creator><slash:comments>0</slash:comments><comments>http://community.ca.com/blogs/casecurityresponseblog/archive/2011/08/12/ca20110809-01-security-notice-for-ca-arcserve-d2d.aspx#comments</comments><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Vulnerability/default.aspx">Vulnerability</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/ARCserve+Backup/default.aspx">ARCserve Backup</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/exploit/default.aspx">exploit</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/rgod/default.aspx">rgod</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/D2D/default.aspx">D2D</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/ARCserve/default.aspx">ARCserve</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CVE-2011-3011/default.aspx">CVE-2011-3011</category><description>On August 9, 2011, we published a security notice and fix to address a high risk vulnerability in ARCserve D2D r15.&amp;nbsp; The vulnerability, CVE-2011-3011, is due to improper session handling. A remote attacker can potentially access credentials and execute arbitrary commands.&amp;nbsp; Vulnerability and exploit details were originally disclosed on BugTraq on July 26, 2011, and CA was not contacted...&lt;br/&gt;
&lt;br/&gt;
&amp;nbsp;&lt;img src="http://feeds.feedburner.com/~r/CaSecurityResponseBlog/~4/yH6htYqrnxA" height="1" width="1"/&gt;</description><feedburner:origLink>http://community.ca.com/blogs/casecurityresponseblog/archive/2011/08/12/ca20110809-01-security-notice-for-ca-arcserve-d2d.aspx</feedburner:origLink></item><item><title>ARCserve D2D public disclosure of vulnerability and exploit details</title><link>http://feeds.ca.com/~r/CaSecurityResponseBlog/~3/hC1hM7G6aMU/arcserve-d2d-public-disclosure-of-vulnerability-and-exploit-details.aspx</link><pubDate>Tue, 26 Jul 2011 18:30:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:7560</guid><dc:creator>Ken Williams</dc:creator><slash:comments>0</slash:comments><comments>http://community.ca.com/blogs/casecurityresponseblog/archive/2011/07/26/arcserve-d2d-public-disclosure-of-vulnerability-and-exploit-details.aspx#comments</comments><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Vulnerability/default.aspx">Vulnerability</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/exploit/default.aspx">exploit</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/rgod/default.aspx">rgod</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/D2D/default.aspx">D2D</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/ARCserve/default.aspx">ARCserve</category><description>CA Technologies is aware of ARCserve D2D vulnerability and exploit details that were posted to BugTraq on 2011-07-26.&amp;nbsp; We&amp;#39;re currently reviewing the information and will post an update after we have completed our initial investigation.

Thanks and regards,
Ken Williams, Director
CA Technologies Product Vulnerability Response Team
CA Technologies Business Unit Operations
wilja22@ca.com...&lt;br/&gt;
&lt;br/&gt;
&amp;nbsp;&lt;img src="http://feeds.feedburner.com/~r/CaSecurityResponseBlog/~4/hC1hM7G6aMU" height="1" width="1"/&gt;</description><feedburner:origLink>http://community.ca.com/blogs/casecurityresponseblog/archive/2011/07/26/arcserve-d2d-public-disclosure-of-vulnerability-and-exploit-details.aspx</feedburner:origLink></item></channel></rss>

