PT-2017-7725 · Ca · Ca Service Desk Management+1

Published

2017-01-18

·

Updated

2017-01-20

·

CVE-2016-10086

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions CA Service Desk Manager version 12.9 CA Service Desk Management version 14.1
Description The issue concerns incorrect permissions applied to RESTful requests, potentially allowing remote authenticated users to read or modify task information.
Recommendations For CA Service Desk Manager version 12.9, update the permissions for RESTful requests to ensure proper access control. For CA Service Desk Management version 14.1, review and correct the permissions applied to RESTful requests to prevent unauthorized access to task information.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-10086

Affected Products

Ca Service Desk Management
Ca Service Desk Manager