CVE-2007-0060

UnknownEPSS 23.64%

Last modified

CVE-2007-0060 is a vulnerability of currently unknown severity. Stack-based buffer overflow in the Message Queuing Server (Cam.exe) in CA (formerly Computer Associates) Message Queuing (CAM / CAFT) software before 1.11 Build 54_4 on Windows and NetWare, as used in CA Advantage Data Transport, eTrust Admin, certain BrightStor products, certain CleverPath products, and certain Unicenter products, allows remote attackers to execute arbitrary code via a crafted message to TCP port 3104.. EPSS estimates a 23.64% chance of exploitation in the next 30 days.

Description

Stack-based buffer overflow in the Message Queuing Server (Cam.exe) in CA (formerly Computer Associates) Message Queuing (CAM / CAFT) software before 1.11 Build 54_4 on Windows and NetWare, as used in CA Advantage Data Transport, eTrust Admin, certain BrightStor products, certain CleverPath products, and certain Unicenter products, allows remote attackers to execute arbitrary code via a crafted message to TCP port 3104.

Metrics

EPSS Probability
23.64%

97.5th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersionsUpdate
BroadcomAdvantage Data Transport3.0
BroadcomBrightstor Portal11.1
BroadcomBrightstor San Manager11.1
BroadcomBrightstor San Manager11.5
BroadcomCleverpath Aion10.0
BroadcomCleverpath Ecm3.5
BroadcomCleverpath Olap5.1
BroadcomCleverpath Predictive Analysis Server2.0
BroadcomCleverpath Predictive Analysis Server3.0
BroadcomEtrust Admin8.0
BroadcomEtrust Admin8.1
BroadcomUnicenter Application Performance Monitor3.0
BroadcomUnicenter Application Performance Monitor3.5
BroadcomUnicenter Asset Management3.1
BroadcomUnicenter Asset Management3.2
BroadcomUnicenter Asset Management4.0
BroadcomUnicenter Data Transport Option2.0
BroadcomUnicenter Jasmine3.0
BroadcomUnicenter Network And Systems Management3.0
BroadcomUnicenter Network And Systems Management3.1
BroadcomUnicenter Nsm Wireless Network Management Option3.0
BroadcomUnicenter Remote Control6.0
BroadcomUnicenter Service Level Management3.0
BroadcomUnicenter Service Level Management3.0.1
BroadcomUnicenter Service Level Management3.0.2
BroadcomUnicenter Service Level Management3.5
BroadcomUnicenter Software Delivery3.0
BroadcomUnicenter Software Delivery3.1
BroadcomUnicenter Software Delivery4.0
BroadcomUnicenter Tng2.1
BroadcomUnicenter Tng2.2
BroadcomUnicenter Tng2.4
BroadcomUnicenter Tng2.4.2
CaEtrust Admin2.1
CaEtrust Admin2.4
CaEtrust Admin2.7
CaEtrust Admin2.9
CaUnicenter Asset Management4.0Sp1
CaUnicenter Enterprise Job Manager1.0Sp1
CaUnicenter Management4.0
CaUnicenter Management4.1
CaUnicenter Management5.0
CaUnicenter Management5.0.1
CaUnicenter Software Delivery4.0Sp1
CaUnicenter Tng2.2

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2007-0060?
Stack-based buffer overflow in the Message Queuing Server (Cam.exe) in CA (formerly Computer Associates) Message Queuing (CAM / CAFT) software before 1.11 Build 54_4 on Windows and NetWare, as used in CA Advantage Data Transport, eTrust Admin, certain BrightStor products, certain CleverPath products, and certain Unicenter products, allows remote attackers to execute arbitrary code via a crafted message to TCP port 3104.
How severe is CVE-2007-0060?
Severity scoring for CVE-2007-0060 is pending analysis. The EPSS model estimates a 23.64% probability of exploitation in the next 30 days.
How do I fix CVE-2007-0060?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2007-0060?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST