CVE-2016-1542

The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attackers to bypass authorization and enumerate users by sending an action packet to xmlrpc after an authorization failure.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
certccCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 98%
VendorProductVersion
bmcbladelogic_server_automation_console
8.2.02
bmcbladelogic_server_automation_console
8.2.03
bmcbladelogic_server_automation_console
8.2.04
bmcbladelogic_server_automation_console
8.3.00
bmcbladelogic_server_automation_console
8.3.01
bmcbladelogic_server_automation_console
8.3.02
bmcbladelogic_server_automation_console
8.3.03
bmcbladelogic_server_automation_console
8.5.00
bmcbladelogic_server_automation_console
8.5.01
bmcbladelogic_server_automation_console
8.6.00
bmcbladelogic_server_automation_console
8.7.00
𝑥
= Vulnerable software versions