CA XOsoft Multiple Products xosoapapi.asmx Buffer Overflow

  Severity: CRITICAL
  CVE Identifier: CVE-2010-1223

  DESCRIPTION

Multiple buffer overflows in CA XOsoft r12.0 and r12.5 allow remote attackers to execute arbitrary code via (1) a malformed request to the ws_man/xosoapapi.asmx SOAP endpoint or (2) a long string to the entry_point.aspx service.

  TREND MICRO PROTECTION INFORMATION

Apply associated Trend Micro DPI Rules.

  SOLUTION

  Trend Micro Deep Security DPI Rule Number: 1004298
  Trend Micro Deep Security DPI Rule Name: 1004298 - CA XOsoft Multiple Products xosoapapi.asmx Buffer Overflow

  AFFECTED SOFTWARE AND VERSION

  • ca xosoft_content_distribution r12.0
  • ca xosoft_content_distribution r12.5
  • ca xosoft_high_availability r12.0
  • ca xosoft_high_availability r12.5
  • ca xosoft_replication r12.0
  • ca xosoft_replication r12.5