CVE-2016-9165
CVSS5.0
发布时间 :2017-03-20 12:59:01
修订时间 :2017-03-23 15:46:01
NMPS    

[原文]The get_sessions servlet in CA Unified Infrastructure Management (formerly CA Nimsoft Monitor) before 8.5 and CA Unified Infrastructure Management Snap (formerly CA Nimsoft Monitor Snap) allows remote attackers to obtain active session ids and consequently bypass authentication or gain privileges via unspecified vectors.


[CNNVD]CNNVD数据暂缺。


[机译]译文暂缺.

- CVSS (基础分值)

CVSS分值: 5 [中等(MEDIUM)]
机密性影响: PARTIAL [很可能造成信息泄露]
完整性影响: NONE [不会对系统完整性产生影响]
可用性影响: NONE [对系统可用性无影响]
攻击复杂度: LOW [漏洞利用没有访问限制 ]
攻击向量: NETWORK [攻击者不需要获取内网访问权或本地访问权]
身份认证: NONE [漏洞利用无需身份认证]

- CWE (弱点类目)

CWE-200 [信息暴露]

- CPE (受影响的平台与产品)

cpe:/a:ca:unified_infrastructure_management_snap:8.47
cpe:/a:ca:unified_infrastructure_management:8.47

- OVAL (用于检测的技术细节)

未找到相关OVAL定义

- 官方数据库链接

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9165
(官方数据源) MITRE
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-9165
(官方数据源) NVD

- 其它链接及资源

http://www.securityfocus.com/bid/94257
(VENDOR_ADVISORY)  BID  94257
http://www.zerodayinitiative.com/advisories/ZDI-16-606
(VENDOR_ADVISORY)  MISC  http://www.zerodayinitiative.com/advisories/ZDI-16-606
https://www.ca.com/us/services-support/ca-support/ca-support-online/product-content/recommended-reading/security-notices/ca20161109-01-security-notice-for-ca-unified-infrastructure-mgmt.html
(VENDOR_ADVISORY)  CONFIRM  https://www.ca.com/us/services-support/ca-support/ca-support-online/product-content/recommended-reading/security-notices/ca20161109-01-security-notice-for-ca-unified-infrastructure-mgmt.html

- 漏洞信息 (F139661)

CA Unified Infrastructure Management Bypass / Traversal / Disclosure (PacketStormID:F139661)
2016-11-10 00:00:00
Ken Williams  www3.ca.com
advisory,remote,vulnerability,info disclosure
CVE-2016-5803,CVE-2016-9164,CVE-2016-9165
[点击下载]

CA Technologies Support is alerting customers to three vulnerabilities in CA Unified Infrastructure Management (formerly CA Nimsoft). The first vulnerability, CVE-2016-9165, involves insecure handling of sessions IDs. A remote attacker can potentially acquire a session ID and bypass authentication or elevate privileges. The second vulnerability, CVE-2016-9164, is a path traversal information disclosure vulnerability associated with the diag.jsp file. A remote attacker can potentially access sensitive information. The third vulnerability, CVE-2016-5803, is a path traversal information disclosure vulnerability associated with the download_lar.jsp file. A remote attacker can potentially access sensitive information. CA Technologies has assigned Medium and High risk ratings to these vulnerabilities. Solutions are available.

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

CA20161109-01: Security Notice for CA Unified Infrastructure Management

Issued: November 09, 2016

CA Technologies Support is alerting customers to three vulnerabilities in 
CA Unified Infrastructure Management (formerly CA Nimsoft).  The first 
vulnerability, CVE-2016-9165, involves insecure handling of sessions IDs.  
A remote attacker can potentially acquire a session ID and bypass 
authentication or elevate privileges.  The second vulnerability, 
CVE-2016-9164, is a path traversal information disclosure vulnerability 
associated with the diag.jsp file.  A remote attacker can potentially 
access sensitive information.  The third vulnerability, CVE-2016-5803, is 
a path traversal information disclosure vulnerability associated with the 
download_lar.jsp file.  A remote attacker can potentially access sensitive 
information.  CA Technologies has assigned Medium and High risk ratings to 
these vulnerabilities.  Solutions are available.


Risk Rating

CVE-2016-9164 - Medium 
CVE-2016-9165 - Medium
CVE-2016-5803 - High


Platform(s)

All


Affected Products

CA Unified Infrastructure Management 8.4 SP1 and earlier (formerly CA 
Nimsoft Monitor)
CA Unified Infrastructure Management Snap (formerly CA Nimsoft Monitor 
Snap)


How to determine if the installation is affected

Check the installed product version.


Solution

Upgrade to CA Unified Infrastructure Management r8.4 SP2 or later.  We 
recommend installing the latest release, CA Unified Infrastructure 
Management r8.47.

If you are unable to upgrade to CA Unified Infrastructure Management r8.47 
at this time, you can alternatively upgrade to CA Unified Infrastructure 
Management r8.4 SP2.  To access r8.4 SP2, go to the Download Center at 
https://support.ca.com/, select product "CA Unified Infrastructure Mgmt 
Server Pack- On Prem - MULTI-PLATFORM", and then select release
"8.4".  CA 
Unified Infrastructure Management r8.4 SP2 can then be found on the 
subsequent Product Download page.


Workaround

None


References

CVE-2016-9165 - CA UIM Session ID Vulnerability
CVE-2016-9164 - CA UIM diag.jsp Path Traversal Vulnerability
CVE-2016-5803 - CA UIM download_lar.jsp Path Traversal Vulnerability


Acknowledgement

CVE-2016-9165 - rgod working with Trend Micro's Zero Day Initiative
CVE-2016-9164 - rgod working with Trend Micro's Zero Day Initiative
CVE-2016-5803 - rgod working with Trend Micro's Zero Day Initiative


Change History

Version 1.0:  Initial Release, 2016-11-09


If additional information is required, please contact CA Technologies 
Support at https://support.ca.com/

If you discover a vulnerability in CA Technologies products, please report 
your findings to the CA Technologies Product Vulnerability Response Team 
at vuln <AT> ca.com

CA Technologies Security Notices can be found at https://support.ca.com/
CA Product Vulnerability Response Team PGP Key:
https://www.ca.com/us/support/ca-support-online/documents.aspx?id=177782


Regards,

Ken Williams
Vulnerability Response Director, CA Product Vulnerability Response Team


Copyright (c) 2016 CA. All Rights Reserved. 520 Madison Avenue, 22nd 
Floor, New York, NY 10022. All other trademarks, trade names, service 
marks, and logos referenced herein belong to their respective companies.

-----BEGIN PGP SIGNATURE-----
Version: Encryption Desktop 10.3.2 (Build 16620)
Charset: utf-8

wsFVAwUBWCO8yzuotw2cX+zOAQqDuhAAgSxI5amAsDgEmSdYvzsWHCuCr9SJ8Kgz
KuFWAkQoLa7pPft8Y5M4iaGDkxmVnT9QzXJtZKn0bGUiPDh6McxD7dyOxZtSPkVc
4uEvPGWSOBLqn1/Gl4wP5uLumWe9wzSN5CvHA7udDflQfyeD5RqljEaQwfCWT7IX
EebuzD+E51Bl/OmRiEtc1/gLuZ/ATq6RaL5jI+hRtg6IVjIM3YdbWSEr0jXqPQyE
qdYRYcKIuPqxs9eZJ2rW+wFFGrsuAeeOBdBcfQmyoe2T9GzDgokuDWGesdtJOGWu
SR2TRdt2BoRtu1E+qIcAnZAav/NXgGSLbXvVPWh8Dc6xRQFAxBkGTr0PkDwHjASI
gN7YMGGfZRAzMYSElJxXnf9S2IqBJjRmbxx7sMWOBOqA0/Pnv1OZ5FfNrYbH1Bye
b9N1nU3SaDYky4R8mWh7TOnk9I91wLg6YmEZNhfk6sMnq49WPz1cWFISBuj+gI2z
0TYk0LX9g6wW12uNS8KdynvcBTeHi527cvV5ThoGKfT6BoY3BwX3LFnM++nA2vtI
rhwgDyJ9lxgqR8lEFKZQBJanSRYR9Zb+bhuSRBsaYo/ZesApWpdGg0LlsJcLKfXe
VJbrr8sP0BGLrukm4lNt20EiusOLazZ6ObikLjDbJiQjhBALcvOr1Lsd2JE+dGJG
NnQWLayjcHI=
=DjVa
-----END PGP SIGNATURE-----
    

- 漏洞信息

CA Unified Infrastructure Management Directory Traversal And Security Bypass Vulnerabilities
Input Validation Error 94257
Yes No
2016-11-10 12:00:00 2016-11-11 02:06:00
rgod working with Trend Micro's Zero Day Initiative.

- 受影响的程序版本

Ca Unified Infrastructure Management 8.4 Service Pack 1
,Ca Unified Infrastructure Management 8.47

- 不受影响的程序版本

Ca Unified Infrastructure Management 8.47

- 漏洞讨论

CA Unified Infrastructure Management is prone to a directory-traversal vulnerability and a security-bypass vulnerability.

Exploiting these issues will allow an attacker to bypass security restrictions, perform unauthorized actions and access, read and execute files. Information harvested may aid in launching further attacks.

- 漏洞利用

Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: vuldb@securityfocus.com.

- 解决方案

Updates are available. Please see the references or vendor advisory for more information.

- 相关参考

 

 

关于SCAP中文社区

SCAP中文社区是国内第一个以SCAP为主题的中文开放社区。了解更多信息,请查阅[关于本站]

版权声明

CVE/CWE/OVAL均为MITRE公司的注册商标,它们的官方数据源均保存在MITRE公司的相关网站