CVE-2016-1543
Summary
| CVE | CVE-2016-1543 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-06-13 14:59:00 UTC |
| Updated | 2018-10-09 19:59:00 UTC |
| Description | The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attackers to bypass authorization and reset arbitrary user passwords by sending an action packet to xmlrpc after an authorization failure. |
Risk And Classification
Problem Types: CWE-284
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| BMC BladeLogic: CVE-2016-1542 and CVE-2016-1543 – Insinuator.net | MISC | www.insinuator.net | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| KnowledgeArticle - BMC | CONFIRM | selfservice.bmc.com | Patch, Vendor Advisory |
| BMC Server Automation RSCD Agent - NSH Remote Command Execution (Metasploit) - Multiple remote Exploit | EXPLOIT-DB | www.exploit-db.com | |
| BMC BladeLogic 8.3.00.64 - Remote Command Execution - Multiple remote Exploit | EXPLOIT-DB | www.exploit-db.com | |
| BMC Server Automation (BSA) RSCD Agent Unauthorized Password Reset ≈ Packet Storm | MISC | packetstormsecurity.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.