CVE-2016-1542
Summary
| CVE | CVE-2016-1542 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-06-13 14:59:00 UTC |
| Updated | 2018-10-09 19:59:00 UTC |
| Description | The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attackers to bypass authorization and enumerate users by sending an action packet to xmlrpc after an authorization failure. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| BMC BladeLogic: CVE-2016-1542 and CVE-2016-1543 – Insinuator.net | MISC | www.insinuator.net | |
| BMC Server Automation (BSA) RSCD Agent User Enumeration ≈ Packet Storm | MISC | packetstormsecurity.com | |
| KnowledgeArticle - BMC | CONFIRM | selfservice.bmc.com | Patch, Vendor Advisory |
| BMC Server Automation RSCD Agent - NSH Remote Command Execution (Metasploit) - Multiple remote Exploit | EXPLOIT-DB | www.exploit-db.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| BMC BladeLogic 8.3.00.64 - Remote Command Execution - Multiple remote Exploit | EXPLOIT-DB | www.exploit-db.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.