{"$ref":"https://www.cert.ssi.gouv.fr/openapi.json","affected_systems":[{"description":"Unicenter Workload Control Center r1 SP4 ;","product":{"name":"N/A","vendor":{"name":"N/A","scada":false}}},{"description":"Unicenter Database Management Portal r11 ;","product":{"name":"Portal","vendor":{"name":"Liferay","scada":false}}},{"description":"eTrust Security Command Center r8 ;","product":{"name":"Security","vendor":{"name":"ESET","scada":false}}},{"description":"Unicenter Management Portal r11.0.","product":{"name":"Portal","vendor":{"name":"Liferay","scada":false}}},{"description":"Unicenter Management Portal r2.0 ;","product":{"name":"Portal","vendor":{"name":"Liferay","scada":false}}},{"description":"CleverPath Aion BPM r10.1 ;","product":{"name":"N/A","vendor":{"name":"N/A","scada":false}}},{"description":"CleverPath Portal r4.71 ;","product":{"name":"Portal","vendor":{"name":"Liferay","scada":false}}},{"description":"eTrust Security Command Center r1 ;","product":{"name":"Security","vendor":{"name":"ESET","scada":false}}},{"description":"CleverPath Aion BPM r10 ;","product":{"name":"N/A","vendor":{"name":"N/A","scada":false}}},{"description":"Unicenter Database Command Center r11.1 ;","product":{"name":"N/A","vendor":{"name":"N/A","scada":false}}},{"description":"CleverPath Portal r4.51 ;","product":{"name":"Portal","vendor":{"name":"Liferay","scada":false}}},{"description":"CleverPath Aion BPM r10.2 ;","product":{"name":"N/A","vendor":{"name":"N/A","scada":false}}},{"description":"CleverPath Portal r4.7 ;","product":{"name":"Portal","vendor":{"name":"Liferay","scada":false}}},{"description":"BrightStor Portal r11.1 ;","product":{"name":"Portal","vendor":{"name":"Liferay","scada":false}}},{"description":"Unicenter Asset and Portfolio Management r11 ;","product":{"name":"N/A","vendor":{"name":"N/A","scada":false}}},{"description":"Unicenter Enterprise Job Manager r1 SP3 ;","product":{"name":"N/A","vendor":{"name":"N/A","scada":false}}},{"description":"Unicenter Management Portal r3.1 ;","product":{"name":"Portal","vendor":{"name":"Liferay","scada":false}}}],"affected_systems_content":null,"content":"## Description\n\nUne vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans Computer Associates CleverPath\nPortal lorsqu'il est d\u00e9ploy\u00e9 dans un environnement multi-serveur. Un\nutilisateur s'authentifiant aupr\u00e8s d'un des portails peut r\u00e9cup\u00e9rer la\nsession d'un utilisateur connect\u00e9 \u00e0 un autre portail sur la m\u00eame\nmachine.\n\n## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l'\u00e9diteur pour l'obtention des\ncorrectifs (cf. section Documentation).\n","cves":[{"name":"CVE-2006-6641","url":"https://www.cve.org/CVERecord?id=CVE-2006-6641"}],"links":[{"title":"Bulletin de s\u00e9curit\u00e9 Computer Associates du 19 d\u00e9cembre    2006 :","url":"http://supportconnectw.ca.com/public/ca_common_docs/cpportal_secnot.asp"}],"reference":"CERTA-2006-AVI-567","revisions":[{"description":"version initiale.","revision_date":"2006-12-21T00:00:00.000000"}],"risks":[{"description":"Contournement de la politique de s\u00e9curit\u00e9"}],"summary":null,"title":"Vuln\u00e9rabilit\u00e9 dans Computer Associates CleverPath","vendor_advisories":[{"published_at":null,"title":"Bulletin de s\u00e9curit\u00e9 Computer Associates du 19 d\u00e9cembre 2006","url":null}]}
