First published: Mon Mar 20 2017(Updated: )
The get_sessions servlet in CA Unified Infrastructure Management (formerly CA Nimsoft Monitor) before 8.5 and CA Unified Infrastructure Management Snap (formerly CA Nimsoft Monitor Snap) allows remote attackers to obtain active session ids and consequently bypass authentication or gain privileges via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
EMC Unified Infrastructure Manager | <=8.47 | |
CA Technologies Unified Infrastructure Management | <=8.47 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9165 is considered a high-severity vulnerability due to its ability to allow remote attackers to bypass authentication.
To fix CVE-2016-9165, update to a version of CA Unified Infrastructure Management or CA Unified Infrastructure Management Snap that is higher than 8.5.
The potential impacts of CVE-2016-9165 include unauthorized access to session IDs, allowing attackers to gain elevated privileges.
CVE-2016-9165 affects users of CA Unified Infrastructure Management and CA Unified Infrastructure Management Snap versions prior to 8.5.
CVE-2016-9165 is an authentication bypass vulnerability stemming from improper handling of active session IDs in the get_sessions servlet.