4.6
CVE-2015-3318
- EPSS 0.06%
- Published 17.06.2015 10:59:03
- Last modified 12.04.2025 10:46:40
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
CA Common Services, as used in CA Client Automation r12.5 SP01, r12.8, and r12.9; CA Network and Systems Management r11.0, r11.1, and r11.2; CA NSM Job Management Option r11.0, r11.1, and r11.2; CA Universal Job Management Agent; CA Virtual Assurance for Infrastructure Managers (aka SystemEDGE) 12.6, 12.7, 12.8, and 12.9; and CA Workload Automation AE r11, r11.3, r11.3.5, and r11.3.6 on UNIX, does not properly validate an unspecified variable, which allows local users to gain privileges via unknown vectors.
Data is provided by the National Vulnerability Database (NVD)
Ca ≫ Client Automation Versionr12.5 Updatesp01
Ca ≫ Client Automation Versionr12.8
Ca ≫ Client Automation Versionr12.9
Ca ≫ Network And Systems Management Versionr11.2
Ca ≫ Nsm Job Management Option Versionr11.0
Ca ≫ Nsm Job Management Option Versionr11.1
Ca ≫ Nsm Job Management Option Versionr11.2
Ca ≫ Universal Job Management Agent Version-
Ca ≫ Virtual Assurance For Infrastructure Managers Version12.6
Ca ≫ Virtual Assurance For Infrastructure Managers Version12.7
Ca ≫ Virtual Assurance For Infrastructure Managers Version12.8
Ca ≫ Virtual Assurance For Infrastructure Managers Version12.9
Ca ≫ Workload Automation Ae Versionr11.0
Ca ≫ Workload Automation Ae Versionr11.3
Ca ≫ Workload Automation Ae Versionr11.3.5
Ca ≫ Workload Automation Ae Versionr11.3.6
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.06% | 0.183 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.