The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attackers to bypass authorization and enumerate users by sending an action packet to xmlrpc after an authorization failure.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2016-06-13 07:59
Updated : 2018-10-09 12:59
NVD link : CVE-2016-1542
Mitre link : CVE-2016-1542
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
bmc
- bladelogic_server_automation_console