CVE-2007-5084
Multiple SQL injection vulnerabilities in Computer Associates (CA) BrightStor Hierarchical Storage Manager (HSM) before r11.6 allow remote attackers to execute arbitrary SQL commands via CsAgent service commands with opcodes (1) 0x07, (2) 0x08, (3)…
Does this matter?
Lower severity and a low EPSS score (1.81%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple SQL injection vulnerabilities in Computer Associates (CA) BrightStor Hierarchical Storage Manager (HSM) before r11.6 allow remote attackers to execute arbitrary SQL commands via CsAgent service commands with opcodes (1) 0x07, (2) 0x08, (3) 0x09, (4) 0x1E, (5) 0x32, (6) 0x36, (7) 0x40, and possibly others.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 1.81% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- broadcom/brightstor hierarchical storage manager
- Source
- cve@mitre.org
References
- http://dvlabs.tippingpoint.com/advisory/TPTI-07-17
- http://secunia.com/advisories/26914Vendor Advisory
- http://securitytracker.com/id?1018747
- http://supportconnectw.ca.com/public/bstorhsm/infodocs/bstorhsm-secnot.aspPatch
- http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=35692Patch
- http://www.securityfocus.com/archive/1/480808/100/0/threaded
- http://www.securityfocus.com/bid/25823
- http://www.vupen.com/english/advisories/2007/3275Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36828
- http://dvlabs.tippingpoint.com/advisory/TPTI-07-17
- http://secunia.com/advisories/26914Vendor Advisory
- http://securitytracker.com/id?1018747
- http://supportconnectw.ca.com/public/bstorhsm/infodocs/bstorhsm-secnot.aspPatch
- http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=35692Patch
- http://www.securityfocus.com/archive/1/480808/100/0/threaded
- http://www.securityfocus.com/bid/25823
- http://www.vupen.com/english/advisories/2007/3275Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36828
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.