Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2005-3653


Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field.


Security Impact Summary

CVE-2005-3653 is a security vulnerability that . Impacting 34 products from broadcom, from broadcom, from broadcom and 31 others, organizations running these solutions should prioritize assessment and patching.

Historical Context

Originally identified in 2005, this vulnerability predates many modern security frameworks and practices. The vulnerability landscape of that era was characterized by different threat models and less mature defense mechanisms compared to contemporary standards.


Published

2005-12-31T05:00:00.000

Last Modified

2026-04-16T00:27:16.627

Status

Modified

Source

[email protected]

Severity

CVSSv2: 10.0 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-119

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application broadcom brightstor_arcserve_backup 9.01 Yes
Application broadcom brightstor_arcserve_backup 11.1 Yes
Application broadcom brightstor_arcserve_backup 11.5 Yes
Application broadcom brightstor_arcserve_backup_laptops_desktops 11.0 Yes
Application broadcom brightstor_arcserve_backup_laptops_desktops 11.1 Yes
Application broadcom brightstor_portal 11.1 Yes
Application broadcom brightstor_process_automation_manager 11.1 Yes
Application broadcom brightstor_san_manager 11.1 Yes
Application broadcom brightstor_san_manager 11.5 Yes
Application broadcom brightstor_storage_resource_manager 6.3 Yes
Application broadcom brightstor_storage_resource_manager 6.4 Yes
Application broadcom brightstor_storage_resource_manager 11.1 Yes
Application broadcom brightstor_storage_resource_manager 11.5 Yes
Application broadcom etrust_admin 8.1 Yes
Application broadcom etrust_audit_aries 8.0 Yes
Application broadcom etrust_audit_irecorder 1.5 Yes
Application broadcom etrust_audit_irecorder 1.5 Yes
Application broadcom etrust_audit_irecorder 8.0 Yes
Application broadcom etrust_identity_minder 8.0 Yes
Application broadcom etrust_integrated_threat_management 8.0 Yes
Application broadcom itechnology_igateway ≤ 4.0.050615 Yes
Application broadcom unicenter_asset_portfolio_management 11.0 Yes
Application broadcom unicenter_autosys_jm 11.0 Yes
Application broadcom unicenter_service_delivery 11.0 Yes
Application broadcom unicenter_service_desk 11.0 Yes
Application broadcom unicenter_service_desk_knowledge_tools 11.0 Yes
Application broadcom unicenter_service_fulfillment 2.2 Yes
Application broadcom unicenter_service_metric_analysis 11.0 Yes
Application ca brightstor_arcserve_backup 11 Yes
Application ca brightstor_enterprise_backup 10.0 Yes
Application ca brightstor_enterprise_backup 10.5 Yes
Application ca brightstor_enterprise_backup 10.5 Yes
Application ca brightstor_enterprise_backup 10.5 Yes
Application ca etrust_audit_aries 1.5 Yes
Application ca etrust_audit_aries 1.5 Yes
Application ca etrust_directory 8.1_web_components Yes
Application ca etrust_secure_content_manager 8.0 Yes
Application ca unicenter_application_performance_monitor 11.0 Yes
Application ca unicenter_application_server_managment 11.0 Yes
Application ca unicenter_ca_web_services_distributed_management 11.0 Yes
Application ca unicenter_exchange_management_console 11.0 Yes
Application ca unicenter_management 3.5 Yes
Application ca unicenter_management 11.0 Yes
Application ca unicenter_management 11.0 Yes
Application ca unicenter_service_catalog_fulfillment_accounting 11.0 Yes
Application ca unicenter_service_fulfillment 11.0 Yes
Application ca unicenter_service_level_management 11.0 Yes
Application ca unicenter_web_server_management 11.0 Yes
Application ca unicenter_web_services_distributed_management 11.0 Yes

References

How SecUtils Interprets This CVE

SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For broadcom's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.