CA’s support is alerting customers to a security risk with CA Service Desk. A cross-site scripting vulnerability exists that can allow a remote attacker to potentially gain sensitive information. CA has issued patches to address the vulnerability.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/83590/CA20091208-01.txt
Source: https://packetstormsecurity.com/files/83590/CA-Service-Desk-Security-Notice.html

