← Vulnerability feed

Vulnerability record · CVE-2011-1653 · published 18 April 2011

CVE-2011-1653: CA Total Defense UNC Server SQL injection via stored procedures

Broadcom · Total Defense

The Unified Network Control (UNC) Server in CA Total Defense r12 before SE2 contains multiple SQL injection flaws in stored procedures such as UnAssignFunctionalRoles, DeleteFilter, and DeleteReports. Because the vulnerable procedures are reachable over the network without authentication, an attacker can inject arbitrary SQL and fully compromise the application database.

10.0 CVSS 2.0 High EPSS 89% · top 0.2% CWE-89 · SQL injection
10.0CVSS 2.0 base score
89%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
44References
16 Jun 2026Last modified by NVD

Description

Multiple SQL injection vulnerabilities in the Unified Network Control (UNC) Server in CA Total Defense (TD) r12 before SE2 allow remote attackers to execute arbitrary SQL commands via vectors involving the (1) UnAssignFunctionalRoles, (2) UnassignAdminRoles, (3) DeleteFilter, (4) NonAssignedUserList, (5) DeleteReportLayout, (6) DeleteReports, and (7) RegenerateReport stored procedures.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 2.0 score of 10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C) and very high EPSS probability indicate a maximum-severity, remotely exploitable flaw with no authentication required.

What it is

The Unified Network Control (UNC) Server in CA Total Defense r12 before SE2 contains multiple SQL injection flaws in stored procedures such as UnAssignFunctionalRoles, DeleteFilter, and DeleteReports. Because the vulnerable procedures are reachable over the network without authentication, an attacker can inject arbitrary SQL and fully compromise the application database.

Impact

An attacker can execute arbitrary SQL commands, leading to complete loss of confidentiality, integrity, and availability of the affected system. This includes reading or modifying sensitive data and potentially executing operating system commands through database features.

Attack surface

The vulnerability is reachable remotely over the network (AV:N) with no authentication required (Au:N) and low attack complexity (AC:L). No user interaction is needed; the attacker directly sends crafted requests to the UNC Server's stored procedures.

Exploitation

The CVE is not listed in CISA KEV, but EPSS indicates a very high probability of exploitation (0.88655, 99.766th percentile). Multiple public advisories and ZDI references exist, suggesting exploit details are publicly available.

What to do

  • Apply the vendor patch (CA Total Defense r12 SE2 or later) as soon as possible.
  • If patching is not immediately possible, restrict network access to the UNC Server to trusted management hosts only.
  • Validate and sanitize all input passed to the affected stored procedures, or disable them if not required.
  • Monitor database logs for anomalous SQL execution patterns originating from the UNC Server.

Detection

  • Inspect web server and database logs for SQL syntax or unexpected stored procedure calls (e.g., UnAssignFunctionalRoles, DeleteFilter) from external IPs.
  • Deploy network signatures to detect SQL injection attempts targeting the UNC Server endpoints.
  • Monitor for unusual database errors or unexpected data modifications that could indicate successful SQL injection.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://secunia.com/advisories/44097 Vendor Advisory
http://securityreason.com/securityalert/8403
http://securitytracker.com/id?1025353
http://www.securityfocus.com/archive/1/517489/100/0/threaded
http://www.securityfocus.com/archive/1/517490/100/0/threaded
http://www.securityfocus.com/archive/1/517491/100/0/threaded
http://www.securityfocus.com/archive/1/517493/100/0/threaded
http://www.securityfocus.com/archive/1/517494/100/0/threaded
http://www.securityfocus.com/archive/1/517496/100/0/threaded
http://www.securityfocus.com/archive/1/517497/100/0/threaded
http://www.securityfocus.com/archive/1/517498/100/0/threaded
http://www.securityfocus.com/bid/47355
http://www.vupen.com/english/advisories/2011/0977 Vendor Advisory
http://www.zerodayinitiative.com/advisories/ZDI-11-128/
http://www.zerodayinitiative.com/advisories/ZDI-11-129/
http://www.zerodayinitiative.com/advisories/ZDI-11-130/
http://www.zerodayinitiative.com/advisories/ZDI-11-131/
http://www.zerodayinitiative.com/advisories/ZDI-11-132/
http://www.zerodayinitiative.com/advisories/ZDI-11-133/
http://www.zerodayinitiative.com/advisories/ZDI-11-134/
https://exchange.xforce.ibmcloud.com/vulnerabilities/66725
https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=%7BCD065CEC-AFE2-4D9D-8E0B-BE7F6E345866%7D
http://secunia.com/advisories/44097 Vendor Advisory
http://securityreason.com/securityalert/8403
http://securitytracker.com/id?1025353
http://www.securityfocus.com/archive/1/517489/100/0/threaded
http://www.securityfocus.com/archive/1/517490/100/0/threaded
http://www.securityfocus.com/archive/1/517491/100/0/threaded
http://www.securityfocus.com/archive/1/517493/100/0/threaded
http://www.securityfocus.com/archive/1/517494/100/0/threaded
http://www.securityfocus.com/archive/1/517496/100/0/threaded
http://www.securityfocus.com/archive/1/517497/100/0/threaded
http://www.securityfocus.com/archive/1/517498/100/0/threaded
http://www.securityfocus.com/bid/47355
http://www.vupen.com/english/advisories/2011/0977 Vendor Advisory
http://www.zerodayinitiative.com/advisories/ZDI-11-128/
http://www.zerodayinitiative.com/advisories/ZDI-11-129/
http://www.zerodayinitiative.com/advisories/ZDI-11-130/
http://www.zerodayinitiative.com/advisories/ZDI-11-131/
http://www.zerodayinitiative.com/advisories/ZDI-11-132/

Track CVE-2011-1653 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2011-2667Broadcom total defense memory buffer overflow vulnerabilityIcihttp.exe in CA Gateway Security for HTTP, as used in CA Gateway Security 8.1 before 8.1.0.69 and CA Total Defense r12, does not properly parse URL…EPSS 16%7.5CVE-2011-1654Broadcom total defense path traversal vulnerabilityDirectory traversal vulnerability in the Heartbeat Web Service in CA.Itm.Server.ManagementWS.dll in the Management Server in CA Total Defense (TD) r1…EPSS 11%7.5CVE-2011-1655Broadcom total defense vulnerabilityThe management.asmx module in the Management Web Service in the Unified Network Control (UNC) Server in CA Total Defense (TD) r12 before SE2 sends a …EPSS 12%9.8CVE-2026-76461Cisco AsyncOS email parsing SQL injection allows root command executionCisco AsyncOS Software for Cisco Secure Email Gateway fails to properly validate email parsing input, allowing crafted email messages containing mali…KEVEPSS 28%analysed9.3CVE-2026-9586Sangoma Switchvox unauthenticated SQL injection in /pa endpointSangoma Switchvox SMB Edition 8.3 (104997) fails to sanitize the PhoneIP value from XML content beginning with <PolycomIPPhone> before concatenating …KEVEPSS 19%analysed10.0CVE-2026-72898Metabase unauthenticated SQL injection in reset_password endpointMetabase exposes a database endpoint, '/reset_password', that fails to neutralize attacker-supplied SQL, allowing arbitrary SQL injection. Because th…KEVEPSS 19%analysed5.9CVE-2026-60137WordPress WP_Query author__not_in SQL injectionWordPress core fails to properly sanitise the author__not_in parameter of WP_Query in versions before 6.8.6, 6.9.5 and 7.0.2, allowing SQL injection …KEVEPSS 5.9%analysed9.8CVE-2026-9082Drupal core SQL injection in unauthenticated request pathDrupal core contains a SQL injection flaw (CWE-89) caused by improper neutralization of special elements in SQL commands. It affects multiple core br…KEVEPSS 16%analysed

Source: NIST National Vulnerability Database (record CVE-2011-1653), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.