7.8

CVE-2016-9795

The casrvc program in CA Common Services, as used in CA Client Automation 12.8, 12.9, and 14.0; CA SystemEDGE 5.8.2 and 5.9; CA Systems Performance for Infrastructure Managers 12.8 and 12.9; CA Universal Job Management Agent 11.2; CA Virtual Assurance for Infrastructure Managers 12.8 and 12.9; CA Workload Automation AE 11, 11.3, 11.3.5, and 11.3.6 on AIX, HP-UX, Linux, and Solaris allows local users to modify arbitrary files and consequently gain root privileges via vectors related to insufficient validation.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Broadcom ≫ Ca Workload Automation Ae Version 11.0
   Hp ≫ Hp-ux
   Ibm ≫ Aix
   Linux ≫ Linux Kernel
   Oracle ≫ Solaris
Broadcom ≫ Ca Workload Automation Ae Version 11.3
   Hp ≫ Hp-ux
   Ibm ≫ Aix
   Linux ≫ Linux Kernel
   Oracle ≫ Solaris
Broadcom ≫ Ca Workload Automation Ae Version 11.3.5
   Hp ≫ Hp-ux
   Ibm ≫ Aix
   Linux ≫ Linux Kernel
   Oracle ≫ Solaris
Broadcom ≫ Ca Workload Automation Ae Version 11.3.6
   Hp ≫ Hp-ux
   Ibm ≫ Aix
   Linux ≫ Linux Kernel
   Oracle ≫ Solaris
Broadcom ≫ Client Automation Version 12.8
   Hp ≫ Hp-ux
   Ibm ≫ Aix
   Linux ≫ Linux Kernel
   Oracle ≫ Solaris
Broadcom ≫ Client Automation Version 12.9
   Hp ≫ Hp-ux
   Ibm ≫ Aix
   Linux ≫ Linux Kernel
   Oracle ≫ Solaris
Broadcom ≫ Client Automation Version 14.0
   Hp ≫ Hp-ux
   Ibm ≫ Aix
   Linux ≫ Linux Kernel
   Oracle ≫ Solaris
Broadcom ≫ Systemedge Version 5.8.2
   Hp ≫ Hp-ux
   Ibm ≫ Aix
   Linux ≫ Linux Kernel
   Oracle ≫ Solaris
Broadcom ≫ Systemedge Version 5.9
   Hp ≫ Hp-ux
   Ibm ≫ Aix
   Linux ≫ Linux Kernel
   Oracle ≫ Solaris
Broadcom ≫ Systems Performance For Infrastructure Managers Version 12.8
   Hp ≫ Hp-ux
   Ibm ≫ Aix
   Linux ≫ Linux Kernel
   Oracle ≫ Solaris
Broadcom ≫ Systems Performance For Infrastructure Managers Version 12.9
   Hp ≫ Hp-ux
   Ibm ≫ Aix
   Linux ≫ Linux Kernel
   Oracle ≫ Solaris
Ca ≫ Universal Job Management Agent Version 11.2
   Hp ≫ Hp-ux
   Ibm ≫ Aix
   Linux ≫ Linux Kernel
   Oracle ≫ Solaris
Ca ≫ Virtual Assurance For Infrastructure Managers Version 12.8
   Hp ≫ Hp-ux
   Ibm ≫ Aix
   Linux ≫ Linux Kernel
   Oracle ≫ Solaris
Ca ≫ Virtual Assurance For Infrastructure Managers Version 12.9
   Hp ≫ Hp-ux
   Ibm ≫ Aix
   Linux ≫ Linux Kernel
   Oracle ≫ Solaris
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.54% 0.414
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://www.securityfocus.com/archive/1/540062/100/0/threaded
Third Party Advisory
VDB Entry
http://www.securityfocus.com/bid/95819
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1037730
Third Party Advisory
VDB Entry
https://www.ca.com/us/services-support/ca-support/ca-support-online/product-content/recommended-reading/security-notices/ca20170126-01--security-notice-for-ca-common-services-casrvc.html
Vendor Advisory