MEDIUM · 4.6

CVE-2015-3317

CA Common Services, as used in CA Client Automation r12.5 SP01, r12.8, and r12.9; CA Network and Systems Management r11.0, r11.1, and r11.2; CA NSM Job Management Option r11.0, r11.1, and r11.2; CA Un...

Vulnerability Description

CA Common Services, as used in CA Client Automation r12.5 SP01, r12.8, and r12.9; CA Network and Systems Management r11.0, r11.1, and r11.2; CA NSM Job Management Option r11.0, r11.1, and r11.2; CA Universal Job Management Agent; CA Virtual Assurance for Infrastructure Managers (aka SystemEDGE) 12.6, 12.7, 12.8, and 12.9; and CA Workload Automation AE r11, r11.3, r11.3.5, and r11.3.6 on UNIX, does not properly perform bounds checking, which allows local users to gain privileges via unspecified vectors.

CVSS Score

4.6

MEDIUM

AV:L/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
CaClient Automationr12.5
CaNetwork And Systems Managementr11.2
CaNsm Job Management Optionr11.0
CaUniversal Job Management Agent-
CaVirtual Assurance For Infrastructure Managers12.6
CaWorkload Automation Aer11
HpHp-UxAll versions
IbmAixAll versions
LinuxLinux KernelAll versions
OracleSolaris-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-3317?

CVE-2015-3317 is a vulnerability with a CVSS score of 4.6 (MEDIUM). CA Common Services, as used in CA Client Automation r12.5 SP01, r12.8, and r12.9; CA Network and Systems Management r11.0, r11.1, and r11.2; CA NSM Job Management Option r11.0, r11.1, and r11.2; CA Un...

How severe is CVE-2015-3317?

CVE-2015-3317 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-3317?

Check the references section above for vendor advisories and patch information. Affected products include: Ca Client Automation, Ca Network And Systems Management, Ca Nsm Job Management Option, Ca Universal Job Management Agent, Ca Virtual Assurance For Infrastructure Managers.