CVE-2016-5803: Path Traversal
An issue was discovered in CA Unified Infrastructure Management Version 8.47 and earlier. The Unified Infrastructure Management software uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5803?
CVE-2016-5803 has been assigned a medium severity rating due to its potential for unauthorized file access.
How do I fix CVE-2016-5803?
To fix CVE-2016-5803, upgrade to CA Unified Infrastructure Management Version 8.48 or later where the issue is resolved.
What type of vulnerability is CVE-2016-5803?
CVE-2016-5803 is classified as a directory traversal vulnerability.
Which versions of CA Unified Infrastructure Management are affected by CVE-2016-5803?
CVE-2016-5803 affects CA Unified Infrastructure Management versions up to and including 8.47.
What can attackers do with CVE-2016-5803?
Attackers leveraging CVE-2016-5803 can potentially gain access to restricted files by manipulating file paths.