SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2006-6641

Unspecified vulnerability in CA CleverPath Portal before maintenance version 4.71.001_179_060830, as used in multiple products including BrightStor Portal r11.1, CleverPath Aion BPM r10 through r10.2, eTrust Security Command Center r1 and r8, and…

HIGH 7.5EPSS 2.57%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (2.57%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Unspecified vulnerability in CA CleverPath Portal before maintenance version 4.71.001_179_060830, as used in multiple products including BrightStor Portal r11.1, CleverPath Aion BPM r10 through r10.2, eTrust Security Command Center r1 and r8, and Unicenter, does not properly handle when multiple Portal servers are started at the same time and share the same data store, which might cause a Portal user to inherit the session and credentials of a user who is on another Portal server.

CVSS 2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
2.57% probability · 84th percentile
CISA KEV
Not listed
Affected
arcserve/brightstor · broadcom/cleverpath portal · cleverpath/aion bpm · cleverpath/portal · etrust/security command center · unicenter/asset and portfolio management · unicenter/database command center · unicenter/database management portal · unicenter/enterprise job manager · unicenter/management portal · unicenter/workload control center
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.