← Back

CVE-2016-9795

nvd nist
Published: Jan 27, 2017Modified: May 13, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

The casrvc program in CA Common Services, as used in CA Client Automation 12.8, 12.9, and 14.0; CA SystemEDGE 5.8.2 and 5.9; CA Systems Performance for Infrastructure Managers 12.8 and 12.9; CA Universal Job Management Agent 11.2; CA Virtual Assurance for Infrastructure Managers 12.8 and 12.9; CA Workload Automation AE 11, 11.3, 11.3.5, and 11.3.6 on AIX, HP-UX, Linux, and Solaris allows local users to modify arbitrary files and consequently gain root privileges via vectors related to insufficient validation.

Affected (14)

4 products
Ca Workload Automation Ae
Client Automation
Systemedge
2 products
Configuration A
14 vulnerable · 4 platform
Vulnerable SoftwareAffected Versions
Broadcom
Version 11.0
Version 11.3.5
Version 11.3.6
Version 11.3
Broadcom
Version 12.8
Version 12.9
Version 14.0
Broadcom
Version 5.8.2
Version 5.9
Broadcom
Version 12.8
Version 12.9
Version 11.2
Ca
Version 12.8
Version 12.9
Running on/withPlatform Versions
Hp
Hp Ux
All versions
Ibm
Aix
All versions
Linux
Linux Kernel
All versions
Oracle
Solaris
All versions

References (8)

Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.