Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2016-10086


RESTful web services in CA Service Desk Manager 12.9 and CA Service Desk Management 14.1 might allow remote authenticated users to read or modify task information by leveraging incorrect permissions applied to a RESTful request.


Published

2017-01-18T22:59:00.170

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 8.1 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:P/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.0

Impact Score

4.9

Weaknesses
  • Type: Primary
    CWE-264

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ca service_desk_management 14.1 Yes
Application ca service_desk_manager 12.9 Yes
Operating System ibm aix * No
Operating System linux linux_kernel * No
Operating System microsoft windows * No
Operating System oracle solaris * No

References