CVE-2005-3653

UnknownEPSS 18.64%

Last modified

CVE-2005-3653 is a vulnerability of currently unknown severity. Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field.. EPSS estimates a 18.64% chance of exploitation in the next 30 days.

Description

Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field.

Metrics

EPSS Probability
18.64%

96.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
BroadcomBrightstor Arcserve Backup9.01
BroadcomBrightstor Arcserve Backup11.1
BroadcomBrightstor Arcserve Backup11.5
BroadcomBrightstor Arcserve Backup Laptops Desktops11.0
BroadcomBrightstor Arcserve Backup Laptops Desktops11.1
BroadcomBrightstor Portal11.1
BroadcomBrightstor Process Automation Manager11.1
BroadcomBrightstor San Manager11.1
BroadcomBrightstor San Manager11.5
BroadcomBrightstor Storage Resource Manager6.3
BroadcomBrightstor Storage Resource Manager6.4
BroadcomBrightstor Storage Resource Manager11.1
BroadcomBrightstor Storage Resource Manager11.5
BroadcomEtrust Admin8.1
BroadcomEtrust Audit Aries8.0
BroadcomEtrust Audit Irecorder1.5Sp2
BroadcomEtrust Audit Irecorder8.0
BroadcomEtrust Identity Minder8.0
BroadcomEtrust Integrated Threat Management8.0
BroadcomItechnology Igateway<= 4.0.050615
BroadcomUnicenter Asset Portfolio Management11.0
BroadcomUnicenter Autosys Jm11.0
BroadcomUnicenter Service Delivery11.0
BroadcomUnicenter Service Desk11.0
BroadcomUnicenter Service Desk Knowledge Tools11.0
BroadcomUnicenter Service Fulfillment2.2
BroadcomUnicenter Service Metric Analysis11.0
CaBrightstor Arcserve Backup11
CaBrightstor Enterprise Backup10.0
CaBrightstor Enterprise Backup10.5
CaEtrust Audit Aries1.5Sp2
CaEtrust Directory8.1_web_components
CaEtrust Secure Content Manager8.0
CaUnicenter Application Performance Monitor11.0
CaUnicenter Application Server Managment11.0
CaUnicenter Ca Web Services Distributed Management11.0
CaUnicenter Exchange Management Console11.0
CaUnicenter Management3.5
CaUnicenter Management11.0
CaUnicenter Service Catalog Fulfillment Accounting11.0
CaUnicenter Service Fulfillment11.0
CaUnicenter Service Level Management11.0
CaUnicenter Web Server Management11.0
CaUnicenter Web Services Distributed Management11.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2005-3653?
Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field.
How severe is CVE-2005-3653?
Severity scoring for CVE-2005-3653 is pending analysis. The EPSS model estimates a 18.64% probability of exploitation in the next 30 days.
How do I fix CVE-2005-3653?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2005-3653?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST