Multiple buffer overflows in CA XOsoft r12.0 and r12.5 allow remote attackers to execute arbitrary code via (1) a malformed request to the ws_man/xosoapapi.asmx SOAP endpoint or (2) a long string to the entry_point.aspx service.
2010-04-07T15:30:00.627
2025-04-11T00:51:21.963
Deferred
CVSSv2: 10.0 (HIGH)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | ca | xosoft_content_distribution | r12.0 | Yes |
| Application | ca | xosoft_content_distribution | r12.5 | Yes |
| Application | ca | xosoft_high_availability | r12.0 | Yes |
| Application | ca | xosoft_high_availability | r12.5 | Yes |
| Application | ca | xosoft_replication | r12.0 | Yes |
| Application | ca | xosoft_replication | r12.5 | Yes |