First published: Tue Dec 13 2016(Updated: )
BMC BladeLogic Server Automation (BSA) before 8.7 Patch 3 allows remote attackers to bypass authentication and consequently read arbitrary files or possibly have unspecified other impact by leveraging a "logic flaw" in the authentication process.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bmc Bladelogic Server Automation Console | =8.7.00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4322 is classified as a high severity vulnerability due to its ability to allow remote attackers to bypass authentication.
To mitigate CVE-2016-4322, upgrade BMC BladeLogic Server Automation to version 8.7 Patch 3 or later.
CVE-2016-4322 can be exploited to bypass authentication, leading to unauthorized file access and other unspecified impacts.
CVE-2016-4322 affects BMC BladeLogic Server Automation versions prior to 8.7 Patch 3.
Yes, CVE-2016-4322 involves a logic flaw in the authentication process that can be exploited by attackers.