<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.ca.com/~d/styles/itemcontent.css"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" version="2.0"><channel><title>CA Security Response Blog</title><link>http://community.ca.com/blogs/casecurityresponseblog/default.aspx</link><description /><dc:language>en</dc:language><generator>CommunityServer 2007 SP2 (Build: 20611.960)</generator><image><link>http://www.ca.com</link><url>http://www.ca.com/images/icons/logo.gif</url><title>CA</title></image><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.ca.com/CaSecurityResponseBlog" type="application/rss+xml" /><item><title>CA20090615-02: CA Service Desk Tomcat Cross Site Scripting Vulnerability</title><link>http://community.ca.com/blogs/casecurityresponseblog/archive/2009/06/15/ca20090615-02-ca-service-desk-tomcat-cross-site-scripting-vulnerability.aspx</link><pubDate>Tue, 16 Jun 2009 02:30:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:2550</guid><dc:creator>Ken Williams</dc:creator><slash:comments>0</slash:comments><comments>http://community.ca.com/blogs/casecurityresponseblog/archive/2009/06/15/ca20090615-02-ca-service-desk-tomcat-cross-site-scripting-vulnerability.aspx#comments</comments><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CA20090615-02/default.aspx">CA20090615-02</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CVE-2008-1232/default.aspx">CVE-2008-1232</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Service+Desk/default.aspx">Service Desk</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/TEC489643/default.aspx">TEC489643</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Vulnerability/default.aspx">Vulnerability</category><description>On June 15th, 2009, CA published a security notice to address a vulnerability in CA Service Desk.
Title: CA20090615-02: CA Service Desk Tomcat Cross Site Scripting Vulnerability

CA Advisory Reference: CA20090615-02

CA Advisory Date: 2009-06-15

Impact: A remote attacker can inject arbitrary web script or HTML.

Summary: The release of Tomcat as included with CA Service Desk r11.2 is potentially...&lt;br/&gt;
&lt;br/&gt;
&amp;nbsp;&lt;img src="http://feeds.feedburner.com/~r/CaSecurityResponseBlog/~4/ni7-Cq36jYs" height="1" width="1"/&gt;</description></item><item><title>CA20090615-01: CA ARCserve Backup Message Engine Denial of Service Vulnerabilities</title><link>http://community.ca.com/blogs/casecurityresponseblog/archive/2009/06/15/ca20090615-01-ca-arcserve-backup-message-engine-denial-of-service-vulnerabilities.aspx</link><pubDate>Tue, 16 Jun 2009 02:00:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:2549</guid><dc:creator>Ken Williams</dc:creator><slash:comments>0</slash:comments><comments>http://community.ca.com/blogs/casecurityresponseblog/archive/2009/06/15/ca20090615-01-ca-arcserve-backup-message-engine-denial-of-service-vulnerabilities.aspx#comments</comments><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/ARCserve+Backup/default.aspx">ARCserve Backup</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CA20090615-01/default.aspx">CA20090615-01</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CVE-2009-1761/default.aspx">CVE-2009-1761</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Denial+of+Service/default.aspx">Denial of Service</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Message+Engine/default.aspx">Message Engine</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/RO08383/default.aspx">RO08383</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/TEC446265/default.aspx">TEC446265</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Vulnerability/default.aspx">Vulnerability</category><description>&amp;nbsp;

On June 15th, 2009, CA published a security notice to address multiple vulnerabilities in CA ARCserve Backup.

Title: CA20090615-01: CA ARCserve Backup Message Engine Denial of Service Vulnerabilities

CA Advisory Reference: CA20090615-01

CA Advisory Date: 2009-06-15

Reported By: iViZ Security Research Team

Impact: A remote attacker can cause a denial of service.

Summary: CA ARCserve...&lt;br/&gt;
&lt;br/&gt;
&amp;nbsp;&lt;img src="http://feeds.feedburner.com/~r/CaSecurityResponseBlog/~4/8reE-ZxQmV0" height="1" width="1"/&gt;</description></item><item><title>Updated: CA20090126-01:  Security Notice for CA Anti-Virus Engine</title><link>http://community.ca.com/blogs/casecurityresponseblog/archive/2009/05/12/updated-ca20090126-01-security-notice-for-ca-anti-virus-engine.aspx</link><pubDate>Tue, 12 May 2009 13:09:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:2365</guid><dc:creator>Ken Williams</dc:creator><slash:comments>0</slash:comments><comments>http://community.ca.com/blogs/casecurityresponseblog/archive/2009/05/12/updated-ca20090126-01-security-notice-for-ca-anti-virus-engine.aspx#comments</comments><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/arclib+7.3.0.15/default.aspx">arclib 7.3.0.15</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/ARCserve+Backup/default.aspx">ARCserve Backup</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CA20090126-01/default.aspx">CA20090126-01</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CVE-2009-0042/default.aspx">CVE-2009-0042</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/exploit/default.aspx">exploit</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/NSM/default.aspx">NSM</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/patch/default.aspx">patch</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/RO01955/default.aspx">RO01955</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/RO01956/default.aspx">RO01956</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/RO01959/default.aspx">RO01959</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/RO05309/default.aspx">RO05309</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/RO05417/default.aspx">RO05417</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/RO05418/default.aspx">RO05418</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/RO05629/default.aspx">RO05629</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/RO05631/default.aspx">RO05631</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/RO05868/default.aspx">RO05868</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Vulnerability/default.aspx">Vulnerability</category><description>On January 26th, 2009, CA published a security notice to address multiple vulnerabilities in the CA Anti-Virus engine.&amp;nbsp; On May 12th, 2009, CA updated this security notice with CA ARCserve patch solution details.


&amp;nbsp;


Title: CA20090126-01: CA Anti-Virus Engine Detection Evasion Multiple Vulnerabilities




CA Advisory Reference: CA20090126-01


CA Advisory Date: 2009-01-26
CA Advisory...&lt;br/&gt;
&lt;br/&gt;
&amp;nbsp;&lt;img src="http://feeds.feedburner.com/~r/CaSecurityResponseBlog/~4/KoT_NIwDODM" height="1" width="1"/&gt;</description></item><item><title>CA20090429-01: CA ARCserve Backup Apache HTTP Server Multiple Vulnerabilities</title><link>http://community.ca.com/blogs/casecurityresponseblog/archive/2009/04/29/ca20090429-01-ca-arcserve-backup-apache-http-server-multiple-vulnerabilities.aspx</link><pubDate>Wed, 29 Apr 2009 19:25:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:2302</guid><dc:creator>Ken Williams</dc:creator><slash:comments>0</slash:comments><comments>http://community.ca.com/blogs/casecurityresponseblog/archive/2009/04/29/ca20090429-01-ca-arcserve-backup-apache-http-server-multiple-vulnerabilities.aspx#comments</comments><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/apache/default.aspx">apache</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/ARCserve+Backup/default.aspx">ARCserve Backup</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/BrightStor/default.aspx">BrightStor</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Buffer+Overflow/default.aspx">Buffer Overflow</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CA20090429-01/default.aspx">CA20090429-01</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CVE-2003-0132/default.aspx">CVE-2003-0132</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CVE-2004-0747/default.aspx">CVE-2004-0747</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Denial+of+Service/default.aspx">Denial of Service</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/DoS/default.aspx">DoS</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/exploit/default.aspx">exploit</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/httpd/default.aspx">httpd</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Vulnerability/default.aspx">Vulnerability</category><description>On April 29th, 2009, CA published a security notice to address multiple vulnerabilities in CA ARCserve Backup on Solaris, Tru64, HP-UX, and AIX.&amp;nbsp; 

&amp;nbsp;
Title: CA20090429-01: CA ARCserve Backup Apache HTTP Server Multiple Vulnerabilities


CA Advisory Reference: CA20090429-01


CA Advisory Date: 2009-04-29


Reported By:
Apache Software Foundation
David Endler of iDefense
Ulf Harnhammar...&lt;br/&gt;
&lt;br/&gt;
&amp;nbsp;&lt;img src="http://feeds.feedburner.com/~r/CaSecurityResponseBlog/~4/qWmx5xb8Xdo" height="1" width="1"/&gt;</description></item><item><title>CA20090126-01: CA Anti-Virus Engine Detection Evasion Multiple Vulnerabilities</title><link>http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/26/ca20090126-01-ca-anti-virus-engine-detection-evasion-multiple-vulnerabilities.aspx</link><pubDate>Tue, 27 Jan 2009 03:50:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:1826</guid><dc:creator>Ken Williams</dc:creator><slash:comments>0</slash:comments><comments>http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/26/ca20090126-01-ca-anti-virus-engine-detection-evasion-multiple-vulnerabilities.aspx#comments</comments><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/anti-virus/default.aspx">anti-virus</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/arclib+7.3.0.15/default.aspx">arclib 7.3.0.15</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/ARCserve+Backup/default.aspx">ARCserve Backup</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CVE-2009-0042/default.aspx">CVE-2009-0042</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/NSM/default.aspx">NSM</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Vulnerability/default.aspx">Vulnerability</category><description>&amp;nbsp;

On January 26th, 2009, CA published a security notice to address multiple vulnerabilities in the CA Anti-Virus engine.


&amp;nbsp;


Title: CA20090126-01: CA Anti-Virus Engine Detection Evasion Multiple Vulnerabilities

CA Advisory Reference: CA20090126-01

CA Advisory Date: 2009-01-26

Reported By: Thierry Zoller and Sergio Alvarez of n.runs AG

Impact: A remote attacker can evade...&lt;br/&gt;
&lt;br/&gt;
&amp;nbsp;&lt;img src="http://feeds.feedburner.com/~r/CaSecurityResponseBlog/~4/iJz1tvpAVts" height="1" width="1"/&gt;</description></item><item><title>CA20090123-01: Cohesion Tomcat Multiple Vulnerabilities</title><link>http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/23/ca20090123-01-cohesion-tomcat-multiple-vulnerabilities.aspx</link><pubDate>Fri, 23 Jan 2009 23:04:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:1820</guid><dc:creator>Ken Williams</dc:creator><slash:comments>0</slash:comments><comments>http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/23/ca20090123-01-cohesion-tomcat-multiple-vulnerabilities.aspx#comments</comments><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Apache+Tomcat/default.aspx">Apache Tomcat</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Cohesion/default.aspx">Cohesion</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CVE-2005-2090/default.aspx">CVE-2005-2090</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CVE-2005-3510/default.aspx">CVE-2005-3510</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CVE-2006-3835/default.aspx">CVE-2006-3835</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CVE-2006-7195/default.aspx">CVE-2006-7195</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CVE-2006-7196/default.aspx">CVE-2006-7196</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CVE-2007-0450/default.aspx">CVE-2007-0450</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CVE-2007-1355/default.aspx">CVE-2007-1355</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CVE-2007-1358/default.aspx">CVE-2007-1358</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CVE-2007-1858/default.aspx">CVE-2007-1858</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CVE-2007-2449/default.aspx">CVE-2007-2449</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CVE-2007-2450/default.aspx">CVE-2007-2450</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CVE-2007-3382/default.aspx">CVE-2007-3382</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CVE-2007-3385/default.aspx">CVE-2007-3385</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CVE-2007-3386/default.aspx">CVE-2007-3386</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CVE-2008-0128/default.aspx">CVE-2008-0128</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/RO04648/default.aspx">RO04648</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Vulnerability/default.aspx">Vulnerability</category><description>On January 23rd, 2009, CA published a security notice to address multiple vulnerabilities in CA Cohesion Application Configuration Manager.

&amp;nbsp;

Title: CA20090123-01: Cohesion Tomcat Multiple Vulnerabilities

CA Advisory Reference: CA20090123-01

CA Advisory Date: 2009-01-23

Reported By: n/a

Impact: Refer to the CVE identifiers for details.

Summary: Multiple security risks exist in Apache...&lt;br/&gt;
&lt;br/&gt;
&amp;nbsp;&lt;img src="http://feeds.feedburner.com/~r/CaSecurityResponseBlog/~4/B0yaMjkBlEA" height="1" width="1"/&gt;</description></item><item><title>CA20090107-01: CA Service Metric Analysis and CA Service Level Management smmsnmpd Arbitrary Command Execution Vulnerability</title><link>http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/07/ca20090107-01-ca-service-metric-analysis-and-ca-service-level-management-smmsnmpd-arbitrary-command-execution-vulnerability.aspx</link><pubDate>Wed, 07 Jan 2009 21:23:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:1769</guid><dc:creator>Ken Williams</dc:creator><slash:comments>0</slash:comments><comments>http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/07/ca20090107-01-ca-service-metric-analysis-and-ca-service-level-management-smmsnmpd-arbitrary-command-execution-vulnerability.aspx#comments</comments><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CA+Service+Level+Management/default.aspx">CA Service Level Management</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CA20090107-01/default.aspx">CA20090107-01</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CVE-2009-0043/default.aspx">CVE-2009-0043</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/RO04649/default.aspx">RO04649</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/RO04653/default.aspx">RO04653</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/RO04667/default.aspx">RO04667</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Service+Metric+Analysis/default.aspx">Service Metric Analysis</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/SLM/default.aspx">SLM</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/SMA/default.aspx">SMA</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Unicenter/default.aspx">Unicenter</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Vulnerability/default.aspx">Vulnerability</category><description>On January 7th, 2009, CA published a security notice to address a vulnerability in CA Service Metric Analysis and CA Service Level Management. 
&amp;nbsp;
Title: CA20090107-01: CA Service Metric Analysis and CA Service Level Management smmsnmpd Arbitrary Command Execution Vulnerability

CA Advisory Reference: CA20090107-01


CA Advisory Date: 2009-01-07


Reported By: Michel Arboi of Tenable Network...&lt;br/&gt;
&lt;br/&gt;
&amp;nbsp;&lt;img src="http://feeds.feedburner.com/~r/CaSecurityResponseBlog/~4/oCmF83w6Xe8" height="1" width="1"/&gt;</description></item><item><title>CA ARCserve Backup LDBserver Vulnerability</title><link>http://community.ca.com/blogs/casecurityresponseblog/archive/2008/12/10/ca-arcserve-backup-ldbserver-vulnerability.aspx</link><pubDate>Wed, 10 Dec 2008 21:10:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:1699</guid><dc:creator>Ken Williams</dc:creator><slash:comments>0</slash:comments><comments>http://community.ca.com/blogs/casecurityresponseblog/archive/2008/12/10/ca-arcserve-backup-ldbserver-vulnerability.aspx#comments</comments><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/ARCserve+Backup/default.aspx">ARCserve Backup</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/BrightStor/default.aspx">BrightStor</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CVE-2008-5415/default.aspx">CVE-2008-5415</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/LDBserver/default.aspx">LDBserver</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Vulnerability/default.aspx">Vulnerability</category><description>On December 10th, 2008, CA published a security notice to address a vulnerability in CA ARCserve Backup LDBserver.
&amp;nbsp;
Title: CA ARCserve Backup LDBserver Vulnerability


CA Advisory Date: 2008-12-10


Reported By:
Dyon Balding of Secunia Research


Impact: A remote attacker can cause a denial of service or execute arbitrary code.


Summary: CA ARCserve Backup contains a vulnerability that can...&lt;br/&gt;
&lt;br/&gt;
&amp;nbsp;&lt;img src="http://feeds.feedburner.com/~r/CaSecurityResponseBlog/~4/eRGmy-PNl10" height="1" width="1"/&gt;</description></item><item><title>CA ARCserve Backup Multiple Vulnerabilities</title><link>http://community.ca.com/blogs/casecurityresponseblog/archive/2008/10/09/ca-arcserve-backup-multiple-vulnerabilities.aspx</link><pubDate>Thu, 09 Oct 2008 21:23:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:1454</guid><dc:creator>Ken Williams</dc:creator><slash:comments>0</slash:comments><comments>http://community.ca.com/blogs/casecurityresponseblog/archive/2008/10/09/ca-arcserve-backup-multiple-vulnerabilities.aspx#comments</comments><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/ARCserve+Backup/default.aspx">ARCserve Backup</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/BrightStor/default.aspx">BrightStor</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/eEye/default.aspx">eEye</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/exploit/default.aspx">exploit</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/patch/default.aspx">patch</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Vulnerability/default.aspx">Vulnerability</category><description>On October 9th, 2008, CA published a security notice to address multiple vulnerabilities in CA ARCserve Backup.
Title: CA ARCserve Backup Multiple Vulnerabilities

CA Advisory Date: 2008-10-09

Reported By:
Haifei Li of Fortinet&amp;#39;s FortiGuard Global Security Research Team
Vulnerability Research Team of Assurent Secure Technologies, a TELUS Company
Greg Linares of eEye Digital Security

Impact:...&lt;br/&gt;
&lt;br/&gt;
&amp;nbsp;&lt;img src="http://feeds.feedburner.com/~r/CaSecurityResponseBlog/~4/1yQ4Y6bRGuU" height="1" width="1"/&gt;</description></item><item><title>CA Service Desk Multiple Cross-Site Scripting Vulnerabilities</title><link>http://community.ca.com/blogs/casecurityresponseblog/archive/2008/09/25/ca-service-desk-multiple-cross-site-scripting-vulnerabilities.aspx</link><pubDate>Fri, 26 Sep 2008 01:51:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:1438</guid><dc:creator>Ken Williams</dc:creator><slash:comments>0</slash:comments><comments>http://community.ca.com/blogs/casecurityresponseblog/archive/2008/09/25/ca-service-desk-multiple-cross-site-scripting-vulnerabilities.aspx#comments</comments><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CMDB/default.aspx">CMDB</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CVE-2008-4119/default.aspx">CVE-2008-4119</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Service+Desk/default.aspx">Service Desk</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Vulnerability/default.aspx">Vulnerability</category><description>On September 24th, 2008, CA published a security notice to address multiple vulnerabilities in CA Service Desk.
Title: CA Service Desk Multiple Cross-Site Scripting Vulnerabilities


CA Advisory Date: 2008-09-24


Reported By:
Open Security Foundation


Impact: A remote attacker can conduct cross-site scripting attacks.


Summary: CA Service Desk contains multiple vulnerabilities that can allow a...&lt;br/&gt;
&lt;br/&gt;
&amp;nbsp;&lt;img src="http://feeds.feedburner.com/~r/CaSecurityResponseBlog/~4/5BZmCuI1unY" height="1" width="1"/&gt;</description></item><item><title>CA Host-Based Intrusion Prevention System SDK kmxfw.sys Multiple Vulnerabilities</title><link>http://community.ca.com/blogs/casecurityresponseblog/archive/2008/08/12/ca-host-based-intrusion-prevention-system-sdk-kmxfw-sys-multiple-vulnerabilities.aspx</link><pubDate>Tue, 12 Aug 2008 19:04:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:1384</guid><dc:creator>Ken Williams</dc:creator><slash:comments>0</slash:comments><comments>http://community.ca.com/blogs/casecurityresponseblog/archive/2008/08/12/ca-host-based-intrusion-prevention-system-sdk-kmxfw-sys-multiple-vulnerabilities.aspx#comments</comments><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Buffer+Overflow/default.aspx">Buffer Overflow</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CVE-2008-2926/default.aspx">CVE-2008-2926</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CVE-2008-3174/default.aspx">CVE-2008-3174</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Host-Based+Intrusion+Prevention+System/default.aspx">Host-Based Intrusion Prevention System</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/kmxfw.sys/default.aspx">kmxfw.sys</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Vulnerability/default.aspx">Vulnerability</category><description>On August 11th, 2008, CA published a security notice to address two vulnerabilities in the CA Host-Based Intrusion Prevention System SDK.
Title: CA Host-Based Intrusion Prevention System SDK kmxfw.sys Multiple Vulnerabilities

CA Advisory Date: 2008-08-11

Reported By:
CVE-2008-2926 - Tobias Klein
CVE-2008-3174 - Elazar Broad

Impact: A remote attacker can cause a denial of service or possibly...&lt;br/&gt;
&lt;br/&gt;
&amp;nbsp;&lt;img src="http://feeds.feedburner.com/~r/CaSecurityResponseBlog/~4/jaZJWZNSZYw" height="1" width="1"/&gt;</description></item><item><title>CA Products That Embed Ingres Multiple Vulnerabilities</title><link>http://community.ca.com/blogs/casecurityresponseblog/archive/2008/08/06/ca-products-that-embed-ingres-multiple-vulnerabilities.aspx</link><pubDate>Wed, 06 Aug 2008 15:55:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:1373</guid><dc:creator>Ken Williams</dc:creator><slash:comments>0</slash:comments><comments>http://community.ca.com/blogs/casecurityresponseblog/archive/2008/08/06/ca-products-that-embed-ingres-multiple-vulnerabilities.aspx#comments</comments><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/ARCserve+Backup/default.aspx">ARCserve Backup</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/BrightStor/default.aspx">BrightStor</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Buffer+Overflow/default.aspx">Buffer Overflow</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CVE-2008-3356/default.aspx">CVE-2008-3356</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CVE-2008-3357/default.aspx">CVE-2008-3357</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CVE-2008-3389/default.aspx">CVE-2008-3389</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/iDefense/default.aspx">iDefense</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Ingres/default.aspx">Ingres</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Unicenter/default.aspx">Unicenter</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Vulnerability/default.aspx">Vulnerability</category><description>On August 1st, 2008, CA published a security notice to address multiple vulnerabilities in CA products that embed Ingres.
Title: CA Products That Embed Ingres Multiple Vulnerabilities

CA Advisory Date: 2008-08-01

Reported By: iDefense Labs

Impact: A remote attacker can execute arbitrary code, gain privileges, or cause a denial of service condition. 

Summary: CA products that embed Ingres...&lt;br/&gt;
&lt;br/&gt;
&amp;nbsp;&lt;img src="http://feeds.feedburner.com/~r/CaSecurityResponseBlog/~4/lUisq47Yvtk" height="1" width="1"/&gt;</description></item><item><title>CA ARCserve Backup for Laptops and Desktops Server LGServer Service Vulnerability</title><link>http://community.ca.com/blogs/casecurityresponseblog/archive/2008/08/01/ca-arcserve-backup-for-laptops-and-desktops-server-lgserver-service-vulnerability.aspx</link><pubDate>Fri, 01 Aug 2008 10:24:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:1368</guid><dc:creator>Ken Williams</dc:creator><slash:comments>0</slash:comments><comments>http://community.ca.com/blogs/casecurityresponseblog/archive/2008/08/01/ca-arcserve-backup-for-laptops-and-desktops-server-lgserver-service-vulnerability.aspx#comments</comments><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/ARCserve+Backup+for+Laptops+and+Desktops/default.aspx">ARCserve Backup for Laptops and Desktops</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CVE-2008-3175/default.aspx">CVE-2008-3175</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/exploit/default.aspx">exploit</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/LGServer/default.aspx">LGServer</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/QI85497/default.aspx">QI85497</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/RO00912/default.aspx">RO00912</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/RO00913/default.aspx">RO00913</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/RO01150/default.aspx">RO01150</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Vulnerability/default.aspx">Vulnerability</category><description>On July 31st, 2008, CA published a security notice to address a vulnerability in CA ARCserve Backup.
Title: CA ARCserve Backup for Laptops and Desktops Server LGServer Service Vulnerability

CA Advisory Date: 2008-07-31

Reported By: Vulnerability Research Team of Assurent Secure Technologies, a TELUS Company

Impact: A remote attacker can execute arbitrary code or cause a denial of service...&lt;br/&gt;
&lt;br/&gt;
&amp;nbsp;&lt;img src="http://feeds.feedburner.com/~r/CaSecurityResponseBlog/~4/_1AjzbRihcU" height="1" width="1"/&gt;</description></item><item><title>CA ARCserve Backup Discovery Service Denial of Service Vulnerability</title><link>http://community.ca.com/blogs/casecurityresponseblog/archive/2008/06/18/ca-arcserve-backup-discovery-service-denial-of-service-vulnerability.aspx</link><pubDate>Wed, 18 Jun 2008 14:16:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:1287</guid><dc:creator>Ken Williams</dc:creator><slash:comments>0</slash:comments><comments>http://community.ca.com/blogs/casecurityresponseblog/archive/2008/06/18/ca-arcserve-backup-discovery-service-denial-of-service-vulnerability.aspx#comments</comments><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/ARCserve+Backup/default.aspx">ARCserve Backup</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/BrightStor/default.aspx">BrightStor</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CVE-2008-1979/default.aspx">CVE-2008-1979</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Discovery+Service/default.aspx">Discovery Service</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Vulnerability/default.aspx">Vulnerability</category><description>On June 17th, 2008, CA published a security notice to address a vulnerability in CA ARCserve Backup.
&amp;nbsp;
Title: CA ARCserve Backup Discovery Service Denial of Service Vulnerability

CA Advisory Date: 2008-06-17

Reported By: Luigi Auriemma

Impact: A remote attacker can cause a denial of service.

Summary: CA ARCserve Backup contains a vulnerability in the Discovery service (casdscsvc) that...&lt;br/&gt;
&lt;br/&gt;
&amp;nbsp;&lt;img src="http://feeds.feedburner.com/~r/CaSecurityResponseBlog/~4/MM1gEaYqQ9w" height="1" width="1"/&gt;</description></item><item><title>CA Secure Content Manager HTTP Gateway Service FTP Request Vulnerabilities</title><link>http://community.ca.com/blogs/casecurityresponseblog/archive/2008/06/04/ca-secure-content-manager-http-gateway-service-ftp-request-vulnerabilities.aspx</link><pubDate>Wed, 04 Jun 2008 20:28:00 GMT</pubDate><guid isPermaLink="false">8d07cc69-a460-48f1-844d-25b05ba87317:1260</guid><dc:creator>Ken Williams</dc:creator><slash:comments>0</slash:comments><comments>http://community.ca.com/blogs/casecurityresponseblog/archive/2008/06/04/ca-secure-content-manager-http-gateway-service-ftp-request-vulnerabilities.aspx#comments</comments><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Buffer+Overflow/default.aspx">Buffer Overflow</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/CVE-2008-2541/default.aspx">CVE-2008-2541</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/exploit/default.aspx">exploit</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/patch/default.aspx">patch</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Secure+Content+Manager/default.aspx">Secure Content Manager</category><category domain="http://community.ca.com/blogs/casecurityresponseblog/archive/tags/Vulnerability/default.aspx">Vulnerability</category><description>On June 3rd, 2008, CA published a security notice to address multiple vulnerabilities in CA Secure Content Manager.
Title: CA Secure Content Manager HTTP Gateway Service FTP Request Vulnerabilities

CA Advisory Date: 2008-06-03

Reported By: Sebastian Apelt working with ZDI/TippingPoint; Cody Pierce, TippingPoint DVLabs

Impact: A remote attacker can cause a denial of service or execute arbitrary...&lt;br/&gt;
&lt;br/&gt;
&amp;nbsp;&lt;img src="http://feeds.feedburner.com/~r/CaSecurityResponseBlog/~4/dWtU8gAsu7E" height="1" width="1"/&gt;</description></item></channel></rss>
