Vulnerability record · CVE-2011-1653 · published 18 April 2011
CVE-2011-1653: CA Total Defense UNC Server SQL injection via stored procedures
Broadcom · Total Defense
The Unified Network Control (UNC) Server in CA Total Defense r12 before SE2 contains multiple SQL injection flaws in stored procedures such as UnAssignFunctionalRoles, DeleteFilter, and DeleteReports. Because the vulnerable procedures are reachable over the network without authentication, an attacker can inject arbitrary SQL and fully compromise the application database.
Description
Multiple SQL injection vulnerabilities in the Unified Network Control (UNC) Server in CA Total Defense (TD) r12 before SE2 allow remote attackers to execute arbitrary SQL commands via vectors involving the (1) UnAssignFunctionalRoles, (2) UnassignAdminRoles, (3) DeleteFilter, (4) NonAssignedUserList, (5) DeleteReportLayout, (6) DeleteReports, and (7) RegenerateReport stored procedures.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 score of 10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C) and very high EPSS probability indicate a maximum-severity, remotely exploitable flaw with no authentication required.
What it is
The Unified Network Control (UNC) Server in CA Total Defense r12 before SE2 contains multiple SQL injection flaws in stored procedures such as UnAssignFunctionalRoles, DeleteFilter, and DeleteReports. Because the vulnerable procedures are reachable over the network without authentication, an attacker can inject arbitrary SQL and fully compromise the application database.
Impact
An attacker can execute arbitrary SQL commands, leading to complete loss of confidentiality, integrity, and availability of the affected system. This includes reading or modifying sensitive data and potentially executing operating system commands through database features.
Attack surface
The vulnerability is reachable remotely over the network (AV:N) with no authentication required (Au:N) and low attack complexity (AC:L). No user interaction is needed; the attacker directly sends crafted requests to the UNC Server's stored procedures.
Exploitation
The CVE is not listed in CISA KEV, but EPSS indicates a very high probability of exploitation (0.88655, 99.766th percentile). Multiple public advisories and ZDI references exist, suggesting exploit details are publicly available.
What to do
- Apply the vendor patch (CA Total Defense r12 SE2 or later) as soon as possible.
- If patching is not immediately possible, restrict network access to the UNC Server to trusted management hosts only.
- Validate and sanitize all input passed to the affected stored procedures, or disable them if not required.
- Monitor database logs for anomalous SQL execution patterns originating from the UNC Server.
Detection
- Inspect web server and database logs for SQL syntax or unexpected stored procedure calls (e.g., UnAssignFunctionalRoles, DeleteFilter) from external IPs.
- Deploy network signatures to detect SQL injection attempts targeting the UNC Server endpoints.
- Monitor for unusual database errors or unexpected data modifications that could indicate successful SQL injection.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2011-1653 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-1653), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.