Multiple vulnerabilities exist that can allow a remote attacker to gain sensitive information, cause a denial of service, or possibly execute arbitrary code.
Vulnerable Systems:
* CA XOsoft Replication r12.5
* CA XOsoft High Availability r12.5
* CA XOsoft Content Distribution r12.5
* CA XOsoft Replication r12.0
* CA XOsoft High Availability r12.0
* CA XOsoft Content Distribution r12.0
Immune Systems:
* CA XOsoft Replication r4
* CA XOsoft High Availability r4
* CA XOsoft Content Distribution r4
The first vulnerability, CVE-2010-1221, occurs due to a lack of authentication. An attacker can make a SOAP request to enumerate user names. This vulnerability has a low risk rating and affects r12.0 and r12.5 XOsoft products.
The second vulnerability, CVE-2010-1222, occurs due to a lack of authentication. An attacker can make a SOAP request to gain potentially sensitive information. This vulnerability has a low risk rating and affects only r12.5 XOsoft products.
The third set of vulnerabilities, CVE-2010-1223, occurs due to insufficient bounds checking. An attacker can make a request that can cause a buffer overflow which may result in a crash or possibly code execution. These vulnerabilities have a high risk rating and affect r12.0 and r12.5 XOsoft products.
Patch Availability:
CA issued the following patches to address the vulnerabilities.
CA XOsoft Replication r12.5, CA XOsoft High Availability r12.5, CA XOsoft Content Distribution r12.5: RO15016
CA XOsoft Replication r12.0, CA XOsoft High Availability r12.0, CA XOsoft Content Distribution r12.0: RO16643