Vulnerability Description
The RSCD agent in BMC Server Automation before 8.6 SP1 Patch 2 and 8.7 before Patch 3 on Windows might allow remote attackers to bypass authorization checks and make an RPC call via unspecified vectors.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bmc | Server Automation | <= 8.6 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/93948Third Party AdvisoryVDB Entry
- https://docs.bmc.com/docs/display/bsa87/Notification+of+Windows+RSCD+Agent+vulneMitigationVendor Advisory
- https://www.exploit-db.com/exploits/43902/
- https://www.exploit-db.com/exploits/43934/
- http://www.securityfocus.com/bid/93948Third Party AdvisoryVDB Entry
- https://docs.bmc.com/docs/display/bsa87/Notification+of+Windows+RSCD+Agent+vulneMitigationVendor Advisory
- https://www.exploit-db.com/exploits/43902/
- https://www.exploit-db.com/exploits/43934/
FAQ
What is CVE-2016-5063?
CVE-2016-5063 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The RSCD agent in BMC Server Automation before 8.6 SP1 Patch 2 and 8.7 before Patch 3 on Windows might allow remote attackers to bypass authorization checks and make an RPC call via unspecified vector...
How severe is CVE-2016-5063?
CVE-2016-5063 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-5063?
Check the references section above for vendor advisories and patch information. Affected products include: Bmc Server Automation.