4.6
CVE-2015-3317
- EPSS 0.37%
- Veröffentlicht 17.06.2015 10:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
CA Common Services, as used in CA Client Automation r12.5 SP01, r12.8, and r12.9; CA Network and Systems Management r11.0, r11.1, and r11.2; CA NSM Job Management Option r11.0, r11.1, and r11.2; CA Universal Job Management Agent; CA Virtual Assurance for Infrastructure Managers (aka SystemEDGE) 12.6, 12.7, 12.8, and 12.9; and CA Workload Automation AE r11, r11.3, r11.3.5, and r11.3.6 on UNIX, does not properly perform bounds checking, which allows local users to gain privileges via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ca ≫ Client Automation Version r12.5 Update sp01
Ca ≫ Client Automation Version r12.8
Ca ≫ Client Automation Version r12.9
Ca ≫ Network And Systems Management Version r11.2
Ca ≫ Nsm Job Management Option Version r11.0
Ca ≫ Nsm Job Management Option Version r11.1
Ca ≫ Nsm Job Management Option Version r11.2
Ca ≫ Universal Job Management Agent Version -
Ca ≫ Virtual Assurance For Infrastructure Managers Version 12.6
Ca ≫ Virtual Assurance For Infrastructure Managers Version 12.7
Ca ≫ Virtual Assurance For Infrastructure Managers Version 12.8
Ca ≫ Virtual Assurance For Infrastructure Managers Version 12.9
Ca ≫ Workload Automation Ae Version r11
Ca ≫ Workload Automation Ae Version r11.3
Ca ≫ Workload Automation Ae Version r11.3.5
Ca ≫ Workload Automation Ae Version r11.3.6
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.37% | 0.287 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
http://www.ca.com/us/support/ca-support-online/product-content/recommended-reading/security-notices/ca20150604-01-security-notice-for-ca-common-services.aspx
http://www.securityfocus.com/bid/75033
http://www.securitytracker.com/id/1032512
http://www.securitytracker.com/id/1032513