Lucene search

K
cveCertccCVE-2016-1542
HistoryJun 13, 2016 - 2:59 p.m.

CVE-2016-1542

2016-06-1314:59:00
CWE-20
certcc
web.nvd.nist.gov
52
cve-2016-1542
rpc api
rscd agent
bmc bladelogic server automation
authorization bypass
user enumeration
nvd

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.4

Confidence

High

EPSS

0.339

Percentile

97.1%

The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attackers to bypass authorization and enumerate users by sending an action packet to xmlrpc after an authorization failure.

Affected configurations

Nvd
Node
bmcbladelogic_server_automation_consoleMatch8.2.02
OR
bmcbladelogic_server_automation_consoleMatch8.2.03
OR
bmcbladelogic_server_automation_consoleMatch8.2.04
OR
bmcbladelogic_server_automation_consoleMatch8.3.00
OR
bmcbladelogic_server_automation_consoleMatch8.3.01
OR
bmcbladelogic_server_automation_consoleMatch8.3.02
OR
bmcbladelogic_server_automation_consoleMatch8.3.03
OR
bmcbladelogic_server_automation_consoleMatch8.5.00
OR
bmcbladelogic_server_automation_consoleMatch8.5.01
OR
bmcbladelogic_server_automation_consoleMatch8.6.00
OR
bmcbladelogic_server_automation_consoleMatch8.7.00
VendorProductVersionCPE
bmcbladelogic_server_automation_console8.2.02cpe:2.3:a:bmc:bladelogic_server_automation_console:8.2.02:*:*:*:*:*:*:*
bmcbladelogic_server_automation_console8.2.03cpe:2.3:a:bmc:bladelogic_server_automation_console:8.2.03:*:*:*:*:*:*:*
bmcbladelogic_server_automation_console8.2.04cpe:2.3:a:bmc:bladelogic_server_automation_console:8.2.04:*:*:*:*:*:*:*
bmcbladelogic_server_automation_console8.3.00cpe:2.3:a:bmc:bladelogic_server_automation_console:8.3.00:*:*:*:*:*:*:*
bmcbladelogic_server_automation_console8.3.01cpe:2.3:a:bmc:bladelogic_server_automation_console:8.3.01:*:*:*:*:*:*:*
bmcbladelogic_server_automation_console8.3.02cpe:2.3:a:bmc:bladelogic_server_automation_console:8.3.02:*:*:*:*:*:*:*
bmcbladelogic_server_automation_console8.3.03cpe:2.3:a:bmc:bladelogic_server_automation_console:8.3.03:*:*:*:*:*:*:*
bmcbladelogic_server_automation_console8.5.00cpe:2.3:a:bmc:bladelogic_server_automation_console:8.5.00:*:*:*:*:*:*:*
bmcbladelogic_server_automation_console8.5.01cpe:2.3:a:bmc:bladelogic_server_automation_console:8.5.01:*:*:*:*:*:*:*
bmcbladelogic_server_automation_console8.6.00cpe:2.3:a:bmc:bladelogic_server_automation_console:8.6.00:*:*:*:*:*:*:*
Rows per page:
1-10 of 111

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.4

Confidence

High

EPSS

0.339

Percentile

97.1%