CVE-2016-1542: Input Validation
The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attackers to bypass authorization and enumerate users by sending an action packet to xmlrpc after an authorization failure.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1542?
CVE-2016-1542 is categorized as a high severity vulnerability due to its potential for unauthorized user enumeration.
How do I fix CVE-2016-1542?
To fix CVE-2016-1542, you should upgrade your BMC BladeLogic Server Automation to a patched version that addresses the RPC API vulnerability.
What types of attacks can be executed due to CVE-2016-1542?
CVE-2016-1542 allows attackers to bypass authorization and enumerate users, which can lead to further targeted attacks.
Is CVE-2016-1542 present in all versions of BMC BladeLogic Server Automation?
No, CVE-2016-1542 affects specific versions including 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x.
What is the product associated with CVE-2016-1542?
CVE-2016-1542 is associated with BMC BladeLogic Server Automation Console.