CVE-2016-9795
The casrvc program in CA Common Services, as used in CA Client Automation 12.8, 12.9, and 14.0; CA SystemEDGE 5.8.2 and 5.9; CA Systems Performance for Infrastructure Managers 12.8 and 12.9; CA Universal Job Management Agent 11.2; CA Virtual Assurance for Infrastructure Managers 12.8 and 12.9; CA Workload Automation AE 11, 11.3, 11.3.5, and 11.3.6 on AIX, HP-UX, Linux, and Solaris allows local users to modify arbitrary files and consequently gain root privileges via vectors related to insufficient validation.
Published:Jan 27, 2017
Last Modified:Apr 20, 2025
EPS:Jan 27, 2017
EPSS Score:0.0007
CVSS Score:7.8
Affected Products
Vendor
Product
Action
Vendor
Broadcom
Product
Ca Workload Automation Ae
Broadcom
Ca Workload Automation Ae
Vendor
Broadcom
Product
Client Automation
Broadcom
Client Automation
Vendor
Broadcom
Product
Systemedge
Broadcom
Systemedge
Vendor
Broadcom
Product
Systems Performance For Infrastructure Managers
Broadcom
Systems Performance For Infrastructure Managers
Vendor
Ca
Product
Universal Job Management Agent
Ca
Universal Job Management Agent
Vendor
Ca
Product
Virtual Assurance For Infrastructure Managers
Ca
Virtual Assurance For Infrastructure Managers
Vendor
Hp
Product
Hp-ux
Hp
Hp-ux
Vendor
Ibm
Product
Aix
Ibm
Aix
Vendor
Linux
Product
Linux Kernel
Linux
Linux Kernel
Vendor
Oracle
Product
Solaris
Oracle
Solaris
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
