CVE-2007-0060
Stack-based buffer overflow in the Message Queuing Server (Cam.exe) in CA (formerly Computer Associates) Message Queuing (CAM / CAFT) software before 1.11 Build 54_4 on Windows and NetWare, as used in CA Advantage Data Transport, eTrust Admin, certain…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 23.6%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Stack-based buffer overflow in the Message Queuing Server (Cam.exe) in CA (formerly Computer Associates) Message Queuing (CAM / CAFT) software before 1.11 Build 54_4 on Windows and NetWare, as used in CA Advantage Data Transport, eTrust Admin, certain BrightStor products, certain CleverPath products, and certain Unicenter products, allows remote attackers to execute arbitrary code via a crafted message to TCP port 3104.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 23.64% probability · 98th percentile
- CISA KEV
- Not listed
- Affected
- broadcom/advantage data transport · broadcom/brightstor portal · broadcom/brightstor san manager · broadcom/cleverpath aion · broadcom/cleverpath ecm · broadcom/cleverpath olap · broadcom/cleverpath predictive analysis server · broadcom/etrust admin · broadcom/unicenter application performance monitor · broadcom/unicenter asset management · broadcom/unicenter data transport option · broadcom/unicenter jasmine · broadcom/unicenter network and systems management · broadcom/unicenter nsm wireless network management option · broadcom/unicenter remote control · broadcom/unicenter service level management · broadcom/unicenter software delivery · broadcom/unicenter tng · ca/etrust admin · ca/unicenter asset management · +4 more
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/26190Third Party Advisory
- http://supportconnectw.ca.com/public/dto_transportit/infodocs/camsgquevul-secnot.aspVendor Advisory
- http://www.ca.com/us/securityadvisor/newsinfo/collateral.aspx?cid=149809Vendor Advisory
- http://www.iss.net/threats/272.htmlBroken Link
- http://www.securityfocus.com/archive/1/474602/100/0/threaded
- http://www.securityfocus.com/bid/25051Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1018449Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2007/2638Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32234Third Party Advisory, VDB Entry
- http://secunia.com/advisories/26190Third Party Advisory
- http://supportconnectw.ca.com/public/dto_transportit/infodocs/camsgquevul-secnot.aspVendor Advisory
- http://www.ca.com/us/securityadvisor/newsinfo/collateral.aspx?cid=149809Vendor Advisory
- http://www.iss.net/threats/272.htmlBroken Link
- http://www.securityfocus.com/archive/1/474602/100/0/threaded
- http://www.securityfocus.com/bid/25051Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1018449Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2007/2638Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32234Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.