VYPR

XOsoft

by Ca

CVEs (3)

  • CVE-2010-1223Apr 7, 2010
    risk 0.01cvss epss 0.17

    Multiple buffer overflows in CA XOsoft r12.0 and r12.5 allow remote attackers to execute arbitrary code via (1) a malformed request to the ws_man/xosoapapi.asmx SOAP endpoint or (2) a long string to the entry_point.aspx service.

  • CVE-2010-1222Apr 7, 2010
    risk 0.00cvss epss 0.02

    CA XOsoft r12.5 does not properly perform authentication, which allows remote attackers to obtain potentially sensitive information via a SOAP request.

  • CVE-2010-1221Apr 7, 2010
    risk 0.00cvss epss 0.02

    CA XOsoft r12.0 and r12.5 does not properly perform authentication, which allows remote attackers to enumerate usernames via a SOAP request.