Issued: May 01, 2018
Last Updated: May 01, 2018
CA Technologies Support is alerting customers to a potential risk with CA Spectrum. A vulnerability exists that can allow an unauthenticated remote attacker to cause a denial of service. CA has solutions to resolve the vulnerability.
The vulnerability, CVE-2018-6589, occurs due to how a Spectrum network service handles invalid data. A remote attacker can send a request that may disrupt a Spectrum service and potentially cause further product instability.
CA Spectrum 10.1.x
CA Spectrum 10.2.x
CA Spectrum 10.2.3
How to determine if the installation is affected
Use one of the below methods to find the CA Spectrum product version:
CA Technologies published the following solutions to resolve the vulnerability.
CA Spectrum 10.1.x:
CA Spectrum 10.2.x:
Update to CA Spectrum 10.2.3
CVE-2018-6589 - CA Spectrum Denial of Service
CVE-2018-6589 - Francesco Scibetta
Version 1.0: 2018-05-01 - Initial Release
CA customers may receive product alerts and advisories by subscribing to Proactive Notifications.
Customers who require additional information about this notice may contact CA Technologies Support at http://support.ca.com/.
To report a suspected vulnerability in a CA Technologies product, please send a summary to the CA Technologies Product Vulnerability Response Team.