Lucene search

K
nvd[email protected]NVD:CVE-2016-1543
HistoryJun 13, 2016 - 2:59 p.m.

CVE-2016-1543

2016-06-1314:59:01
CWE-284
web.nvd.nist.gov
1

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS

0.339

Percentile

97.1%

The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attackers to bypass authorization and reset arbitrary user passwords by sending an action packet to xmlrpc after an authorization failure.

Affected configurations

Nvd
Node
bmcbladelogic_server_automation_consoleMatch8.2.02
OR
bmcbladelogic_server_automation_consoleMatch8.2.03
OR
bmcbladelogic_server_automation_consoleMatch8.2.04
OR
bmcbladelogic_server_automation_consoleMatch8.3.00
OR
bmcbladelogic_server_automation_consoleMatch8.3.01
OR
bmcbladelogic_server_automation_consoleMatch8.3.02
OR
bmcbladelogic_server_automation_consoleMatch8.3.03
OR
bmcbladelogic_server_automation_consoleMatch8.5.00
OR
bmcbladelogic_server_automation_consoleMatch8.5.01
OR
bmcbladelogic_server_automation_consoleMatch8.6.00
OR
bmcbladelogic_server_automation_consoleMatch8.7.00
VendorProductVersionCPE
bmcbladelogic_server_automation_console8.2.02cpe:2.3:a:bmc:bladelogic_server_automation_console:8.2.02:*:*:*:*:*:*:*
bmcbladelogic_server_automation_console8.2.03cpe:2.3:a:bmc:bladelogic_server_automation_console:8.2.03:*:*:*:*:*:*:*
bmcbladelogic_server_automation_console8.2.04cpe:2.3:a:bmc:bladelogic_server_automation_console:8.2.04:*:*:*:*:*:*:*
bmcbladelogic_server_automation_console8.3.00cpe:2.3:a:bmc:bladelogic_server_automation_console:8.3.00:*:*:*:*:*:*:*
bmcbladelogic_server_automation_console8.3.01cpe:2.3:a:bmc:bladelogic_server_automation_console:8.3.01:*:*:*:*:*:*:*
bmcbladelogic_server_automation_console8.3.02cpe:2.3:a:bmc:bladelogic_server_automation_console:8.3.02:*:*:*:*:*:*:*
bmcbladelogic_server_automation_console8.3.03cpe:2.3:a:bmc:bladelogic_server_automation_console:8.3.03:*:*:*:*:*:*:*
bmcbladelogic_server_automation_console8.5.00cpe:2.3:a:bmc:bladelogic_server_automation_console:8.5.00:*:*:*:*:*:*:*
bmcbladelogic_server_automation_console8.5.01cpe:2.3:a:bmc:bladelogic_server_automation_console:8.5.01:*:*:*:*:*:*:*
bmcbladelogic_server_automation_console8.6.00cpe:2.3:a:bmc:bladelogic_server_automation_console:8.6.00:*:*:*:*:*:*:*
Rows per page:
1-10 of 111

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS

0.339

Percentile

97.1%