Title : CA Clever Path Portal Multi-server Environment Remote Session Hijacking Vulnerability VUPEN ID : VUPEN/ADV-2006-5091 CVE ID : CVE-2006-6641
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-12-20
Technical Description
A vulnerability has been identified in various CA products, which could be exploited by attackers to potentially hijack a user's session. This issue is due to an error in the CleverPath Portal when deployed in a multi-server environment sharing a common data store, which could allow a user who connects through one Portal server to inherit the Portal session and associated security authentication of a user running on another Portal server.
Note : None of the CA products that embed the CleverPath Portal offer a multiple Portal server environment as a configurable option.
Subscribe to VUPEN VNS and receive real-time e-mail and SMS alerts when new advisories or patches relevant to your systems and network configurations are available.
Feedback If you have additional information or corrections for this security advisory please submit them via our contact form.