PT-2017-7725 · Ca · Ca Service Desk Management+1
Publicado
2017-01-18
·
Atualizado
2017-01-20
·
CVE-2016-10086
CVSS v3.1
8.1
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
CA Service Desk Manager version 12.9
CA Service Desk Management version 14.1
Description
The issue concerns incorrect permissions applied to RESTful requests, potentially allowing remote authenticated users to read or modify task information.
Recommendations
For CA Service Desk Manager version 12.9, update the permissions for RESTful requests to ensure proper access control.
For CA Service Desk Management version 14.1, review and correct the permissions applied to RESTful requests to prevent unauthorized access to task information.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ca Service Desk Management
Ca Service Desk Manager