CVE-2005-3653 - CVE House
Back to Database
Status published Critical CVE-2005-3653

Heap-based buffer overflow in the iGateway service for various Computer...

Vulnerability Description

Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2005-3653

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

brightstor arcserve backup, brightstor arcserve backup laptops desktops, brightstor portal, brightstor process automation manager, brightstor san manager, brightstor storage resource manager, etrust admin, etrust audit aries, etrust audit irecorder, etrust identity minder, etrust integrated threat management, itechnology igateway, unicenter asset portfolio management, unicenter autosys jm, unicenter service delivery, unicenter service desk, unicenter service desk knowledge tools, unicenter service fulfillment, unicenter service metric analysis, brightstor enterprise backup, etrust directory, etrust secure content manager, unicenter application performance monitor, unicenter application server managment, unicenter ca web services distributed management, unicenter exchange management console, unicenter management, unicenter service catalog fulfillment accounting, unicenter service level management, unicenter web server management, unicenter web services distributed management
Vulnerable Versions:
9.01, 11.1, 11.5, 11.0, 6.3, 6.4, 8.1, 8.0, 1.5, 0, 2.2, 11, 10.0, 10.5, 8.1_web_components, 3.5

Timeline

Official Publish: January 23rd, 2006
Last Modified: August 7th, 2024
Added to House: July 18th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.