CVE-2016-9795

The casrvc program in CA Common Services, as used in CA Client Automation 12.8, 12.9, and 14.0; CA SystemEDGE 5.8.2 and 5.9; CA Systems Performance for Infrastructure Managers 12.8 and 12.9; CA Universal Job Management Agent 11.2; CA Virtual Assurance for Infrastructure Managers 12.8 and 12.9; CA Workload Automation AE 11, 11.3, 11.3.5, and 11.3.6 on AIX, HP-UX, Linux, and Solaris allows local users to modify arbitrary files and consequently gain root privileges via vectors related to insufficient validation.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 21%
VendorProductVersion
broadcomca_workload_automation_ae
11.0
broadcomca_workload_automation_ae
11.3
broadcomca_workload_automation_ae
11.3.5
broadcomca_workload_automation_ae
11.3.6
broadcomclient_automation
12.8
broadcomclient_automation
12.9
broadcomclient_automation
14.0
broadcomsystemedge
5.8.2
broadcomsystemedge
5.9
broadcomsystems_performance_for_infrastructure_managers
12.8
broadcomsystems_performance_for_infrastructure_managers
12.9
cauniversal_job_management_agent
11.2
cavirtual_assurance_for_infrastructure_managers
12.8
cavirtual_assurance_for_infrastructure_managers
12.9
𝑥
= Vulnerable software versions