PT-2017-7725 · Ca · Ca Service Desk Management+1

Publicado

2017-01-18

·

Atualizado

2017-01-20

·

CVE-2016-10086

CVSS v3.1

8.1

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions CA Service Desk Manager version 12.9 CA Service Desk Management version 14.1
Description The issue concerns incorrect permissions applied to RESTful requests, potentially allowing remote authenticated users to read or modify task information.
Recommendations For CA Service Desk Manager version 12.9, update the permissions for RESTful requests to ensure proper access control. For CA Service Desk Management version 14.1, review and correct the permissions applied to RESTful requests to prevent unauthorized access to task information.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-10086

Produtos afetados

Ca Service Desk Management
Ca Service Desk Manager