CVE-2016-9165: Infoleak
The getsessions servlet in CA Unified Infrastructure Management (formerly CA Nimsoft Monitor) before 8.5 and CA Unified Infrastructure Management Snap (formerly CA Nimsoft Monitor Snap) allows remote attackers to obtain active session ids and consequently bypass authentication or gain privileges via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9165?
CVE-2016-9165 is considered a high-severity vulnerability due to its ability to allow remote attackers to bypass authentication.
How do I fix CVE-2016-9165?
To fix CVE-2016-9165, update to a version of CA Unified Infrastructure Management or CA Unified Infrastructure Management Snap that is higher than 8.5.
What are the potential impacts of CVE-2016-9165?
The potential impacts of CVE-2016-9165 include unauthorized access to session IDs, allowing attackers to gain elevated privileges.
Who is affected by CVE-2016-9165?
CVE-2016-9165 affects users of CA Unified Infrastructure Management and CA Unified Infrastructure Management Snap versions prior to 8.5.
What is the nature of CVE-2016-9165?
CVE-2016-9165 is an authentication bypass vulnerability stemming from improper handling of active session IDs in the get_sessions servlet.