PT-2015-6145 · Ca · Ca Network/Systems Management+5
Published
2015-06-17
·
Updated
2021-04-09
·
CVE-2015-3317
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
CA Client Automation versions r12.5 SP01, r12.8, and r12.9
CA Network and Systems Management versions r11.0, r11.1, and r11.2
CA NSM Job Management Option versions r11.0, r11.1, and r11.2
CA Universal Job Management Agent (affected versions not specified)
CA Virtual Assurance for Infrastructure Managers versions 12.6, 12.7, 12.8, and 12.9
CA Workload Automation AE versions r11, r11.3, r11.3.5, and r11.3.6
Description
The issue is related to improper bounds checking, which allows local users to gain privileges via unspecified vectors.
Recommendations
For CA Client Automation versions r12.5 SP01, r12.8, and r12.9, update to a version that properly performs bounds checking.
For CA Network and Systems Management versions r11.0, r11.1, and r11.2, update to a version that properly performs bounds checking.
For CA NSM Job Management Option versions r11.0, r11.1, and r11.2, update to a version that properly performs bounds checking.
For CA Universal Job Management Agent, at the moment, there is no information about a newer version that contains a fix for this issue.
For CA Virtual Assurance for Infrastructure Managers versions 12.6, 12.7, 12.8, and 12.9, update to a version that properly performs bounds checking.
For CA Workload Automation AE versions r11, r11.3, r11.3.5, and r11.3.6, update to a version that properly performs bounds checking.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ca Client Automation
Ca Nsm Job Management Option
Ca Network/Systems Management
Ca Universal Job Management Agent
Ca Virtual Assurance For Infrastructure Managers
Ca Workload Automation Ae