CVE-2016-9795
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
27/01/2017
Last modified:
20/04/2025
Description
The casrvc program in CA Common Services, as used in CA Client Automation 12.8, 12.9, and 14.0; CA SystemEDGE 5.8.2 and 5.9; CA Systems Performance for Infrastructure Managers 12.8 and 12.9; CA Universal Job Management Agent 11.2; CA Virtual Assurance for Infrastructure Managers 12.8 and 12.9; CA Workload Automation AE 11, 11.3, 11.3.5, and 11.3.6 on AIX, HP-UX, Linux, and Solaris allows local users to modify arbitrary files and consequently gain root privileges via vectors related to insufficient validation.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Base Score 2.0
7.20
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:broadcom:ca_workload_automation_ae:11.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:broadcom:ca_workload_automation_ae:11.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:broadcom:ca_workload_automation_ae:11.3.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:broadcom:ca_workload_automation_ae:11.3.6:*:*:*:*:*:*:* | ||
| cpe:2.3:a:broadcom:client_automation:12.8:*:*:*:*:*:*:* | ||
| cpe:2.3:a:broadcom:client_automation:12.9:*:*:*:*:*:*:* | ||
| cpe:2.3:a:broadcom:client_automation:14.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:broadcom:systemedge:5.8.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:broadcom:systemedge:5.9:*:*:*:*:*:*:* | ||
| cpe:2.3:a:broadcom:systems_performance_for_infrastructure_managers:12.8:*:*:*:*:*:*:* | ||
| cpe:2.3:a:broadcom:systems_performance_for_infrastructure_managers:12.9:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ca:universal_job_management_agent:11.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ca:virtual_assurance_for_infrastructure_managers:12.8:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ca:virtual_assurance_for_infrastructure_managers:12.9:*:*:*:*:*:*:* | ||
| cpe:2.3:o:hp:hp-ux:*:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://www.securityfocus.com/archive/1/540062/100/0/threaded
- http://www.securityfocus.com/bid/95819
- http://www.securitytracker.com/id/1037730
- https://www.ca.com/us/services-support/ca-support/ca-support-online/product-content/recommended-reading/security-notices/ca20170126-01--security-notice-for-ca-common-services-casrvc.html
- http://www.securityfocus.com/archive/1/540062/100/0/threaded
- http://www.securityfocus.com/bid/95819
- http://www.securitytracker.com/id/1037730
- https://www.ca.com/us/services-support/ca-support/ca-support-online/product-content/recommended-reading/security-notices/ca20170126-01--security-notice-for-ca-common-services-casrvc.html



