CVE-2016-9795: Input Validation
The casrvc program in CA Common Services, as used in CA Client Automation 12.8, 12.9, and 14.0; CA SystemEDGE 5.8.2 and 5.9; CA Systems Performance for Infrastructure Managers 12.8 and 12.9; CA Universal Job Management Agent 11.2; CA Virtual Assurance for Infrastructure Managers 12.8 and 12.9; CA Workload Automation AE 11, 11.3, 11.3.5, and 11.3.6 on AIX, HP-UX, Linux, and Solaris allows local users to modify arbitrary files and consequently gain root privileges via vectors related to insufficient validation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9795?
CVE-2016-9795 is classified as a medium severity vulnerability.
How do I fix CVE-2016-9795?
To fix CVE-2016-9795, update the affected CA software to the latest patched version provided by Broadcom.
Which software is affected by CVE-2016-9795?
CVE-2016-9795 affects multiple CA products including CA Client Automation, CA Workload Automation, and CA SystemEDGE across specific versions.
What are the potential risks of CVE-2016-9795?
The risks associated with CVE-2016-9795 primarily involve potential security vulnerabilities that could be exploited by attackers.
Is CVE-2016-9795 present in Broadcom CA Workload Automation AE versions?
Yes, CVE-2016-9795 is present in specific versions of Broadcom CA Workload Automation AE, including versions 11.0, 11.3, 11.3.5, and 11.3.6.