CVE-2016-9148: XSS
Cross-site scripting (XSS) vulnerability in CA Service Desk Manager (formerly CA Service Desk) 12.9 and 14.1 allows remote attackers to inject arbitrary web script or HTML via the QBE.EQ.REFNUM parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9148?
CVE-2016-9148 is classified as a medium severity vulnerability due to its potential impact on sensitive information via cross-site scripting.
How do I fix CVE-2016-9148?
To fix CVE-2016-9148, upgrade to a non-vulnerable version of CA Service Desk Manager, specifically versions after 14.1.
What type of attack does CVE-2016-9148 facilitate?
CVE-2016-9148 facilitates cross-site scripting (XSS) attacks which allow remote attackers to inject malicious scripts.
Which versions of CA Service Desk Manager are affected by CVE-2016-9148?
CVE-2016-9148 affects CA Service Desk Manager versions 12.9 and 14.1.
How can I determine if my system is vulnerable to CVE-2016-9148?
You can determine if your system is vulnerable to CVE-2016-9148 by checking if it is running CA Service Desk Manager version 12.9 or 14.1.