The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attackers to bypass authorization and reset arbitrary user passwords by sending an action packet to xmlrpc after an authorization failure.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2016-06-13 07:59
Updated : 2018-10-09 12:59
NVD link : CVE-2016-1543
Mitre link : CVE-2016-1543
JSON object : View
CWE
CWE-284
Improper Access Control
Products Affected
bmc
- bladelogic_server_automation_console