PT-2017-7725 · Ca · Ca Service Desk Management+1
Published
2017-01-18
·
Updated
2017-01-20
·
CVE-2016-10086
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
CA Service Desk Manager version 12.9
CA Service Desk Management version 14.1
Description
The issue concerns incorrect permissions applied to RESTful requests, potentially allowing remote authenticated users to read or modify task information.
Recommendations
For CA Service Desk Manager version 12.9, update the permissions for RESTful requests to ensure proper access control.
For CA Service Desk Management version 14.1, review and correct the permissions applied to RESTful requests to prevent unauthorized access to task information.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ca Service Desk Management
Ca Service Desk Manager