CVE-2016-5803
Last modified
CVE-2016-5803 is a vulnerability of currently unknown severity. An issue was discovered in CA Unified Infrastructure Management Version 8.47 and earlier. The Unified Infrastructure Management software uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.. EPSS estimates a 2.31% chance of exploitation in the next 30 days.
Description
An issue was discovered in CA Unified Infrastructure Management Version 8.47 and earlier. The Unified Infrastructure Management software uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ca Technologies | Unified Infrastructure Management | <= 8.47 |
References
- http://www.securityfocus.com/bid/94243Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-16-315-01Mitigation, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/94243Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-16-315-01Mitigation, Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-5803?
How severe is CVE-2016-5803?
How do I fix CVE-2016-5803?
Are you affected by CVE-2016-5803?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
