[<prev] [next>] [day] [month] [year] [list]
Message-ID: <1335FF3F144C424F839EFBA7AD8A56E008C5F4D2@USILMS12.ca.com>
Date: Mon, 22 Feb 2010 18:26:10 -0500
From: "Kotas, Kevin J" <Kevin.Kotas@...com>
To: <full-disclosure@...ts.grok.org.uk>
Subject: CA20100222-01: Security Notice for CA Service Desk
-----BEGIN PGP SIGNED MESSAGE-----
CA20100222-01: Security Notice for CA Service Desk
Issued: February 22, 2010
CA's support is alerting customers to a security risk with CA Service
Desk r12.1. The release of Tomcat as included with CA Service Desk
r12.1 is potentially susceptible to a cross-site scripting
vulnerability. CA has issued a technical document that describes
remediation procedures.
Risk Rating
Medium
Platforms
Windows
Unix
Affected Products
CA Service Desk r12.1
How to determine if the installation is affected
Customers can use the instructions in technical document TEC503137 to
determine if an installation may be affected.
Solution
Follow the instructions in technical document TEC503137.
(line may wrap)
https://support.ca.com/irj/portal/anonymous/redirArticles?reqPage=sear
ch&searchID=TEC503137
References
CVE-2008-1947
Change History
Version 1.0: Initial Release
If additional information is required, please contact CA Support at
http://support.ca.com/
If you discover a vulnerability in CA products, please report your
findings to the CA Product Vulnerability Response Team.
-----BEGIN PGP SIGNATURE-----
Version: PGP 8.1
iQEVAwUBS4MO/JI1FvIeMomJAQEJ0AgAtPTeURZRFLbsh94ttXzoTQpkYwXEoFls
SKOYsYZDNXTtlC0x2ZTTRlA0MKMXvCuFPJVFDzhwMs1mkJnL6lf+EkArK1R1B3vW
5IBysmAjrFQN6KONMlD9KMWJeGaaJlCwcA664OUE/tNFhXp+blSet6fKwKU6eHkC
vuhO2RT1+DhkNTRs4QN+aOfjqLrkmA8DnGjQeTA2FLu/l3YroBQHwwlKuXpHNzZ6
RHERx7T0jDzzgtpWRjX6sHTiEW852Ds8ozLSygQJYUByWQBdXbxgsBFpiYi5a66+
D4UcBwdiXiWvYTAbyffs6ViYj/PosWpxirQL1lahfr1K5Mkp/tIpLA==
=t2FJ
-----END PGP SIGNATURE-----
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists