PT-2015-6145 · Ca · Ca Network/Systems Management+5

Published

2015-06-17

·

Updated

2021-04-09

·

CVE-2015-3317

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions CA Client Automation versions r12.5 SP01, r12.8, and r12.9 CA Network and Systems Management versions r11.0, r11.1, and r11.2 CA NSM Job Management Option versions r11.0, r11.1, and r11.2 CA Universal Job Management Agent (affected versions not specified) CA Virtual Assurance for Infrastructure Managers versions 12.6, 12.7, 12.8, and 12.9 CA Workload Automation AE versions r11, r11.3, r11.3.5, and r11.3.6
Description The issue is related to improper bounds checking, which allows local users to gain privileges via unspecified vectors.
Recommendations For CA Client Automation versions r12.5 SP01, r12.8, and r12.9, update to a version that properly performs bounds checking. For CA Network and Systems Management versions r11.0, r11.1, and r11.2, update to a version that properly performs bounds checking. For CA NSM Job Management Option versions r11.0, r11.1, and r11.2, update to a version that properly performs bounds checking. For CA Universal Job Management Agent, at the moment, there is no information about a newer version that contains a fix for this issue. For CA Virtual Assurance for Infrastructure Managers versions 12.6, 12.7, 12.8, and 12.9, update to a version that properly performs bounds checking. For CA Workload Automation AE versions r11, r11.3, r11.3.5, and r11.3.6, update to a version that properly performs bounds checking.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-3317

Affected Products

Ca Client Automation
Ca Nsm Job Management Option
Ca Network/Systems Management
Ca Universal Job Management Agent
Ca Virtual Assurance For Infrastructure Managers
Ca Workload Automation Ae