First published: Wed Jun 17 2015(Updated: )
CA Common Services, as used in CA Client Automation r12.5 SP01, r12.8, and r12.9; CA Network and Systems Management r11.0, r11.1, and r11.2; CA NSM Job Management Option r11.0, r11.1, and r11.2; CA Universal Job Management Agent; CA Virtual Assurance for Infrastructure Managers (aka SystemEDGE) 12.6, 12.7, 12.8, and 12.9; and CA Workload Automation AE r11, r11.3, r11.3.5, and r11.3.6 on UNIX, does not properly validate an unspecified variable, which allows local users to gain privileges via unknown vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom Client Automation | =r12.5-sp01 | |
Broadcom Client Automation | =r12.8 | |
Broadcom Client Automation | =r12.9 | |
CA Network and Systems Management | =r11.2 | |
CA NSM Job Management Option | =r11.0 | |
CA NSM Job Management Option | =r11.1 | |
CA NSM Job Management Option | =r11.2 | |
CA Universal Job Management Agent | ||
CA Virtual Assurance for Infrastructure Managers | =12.6 | |
CA Virtual Assurance for Infrastructure Managers | =12.7 | |
CA Virtual Assurance for Infrastructure Managers | =12.8 | |
CA Virtual Assurance for Infrastructure Managers | =12.9 | |
Broadcom CA Workload Automation AE | =r11.0 | |
Broadcom CA Workload Automation AE | =r11.3 | |
Broadcom CA Workload Automation AE | =r11.3.5 | |
Broadcom CA Workload Automation AE | =r11.3.6 | |
HPE HP-UX | ||
IBM AIX | ||
Linux Kernel | ||
Oracle Solaris and Zettabyte File System (ZFS) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2015-3318 is considered critical due to potential unauthorized access or data manipulation.
To fix CVE-2015-3318, apply the latest security patches and updates provided by Broadcom for all affected software versions.
CVE-2015-3318 affects multiple CA software products including Broadcom Client Automation and CA Network and Systems Management.
While applying updates is the recommended action, review configuration settings to minimize exposure temporarily.
The potential impacts of CVE-2015-3318 include data breaches and disruption of services due to unauthorized access.