CA20161109-01:  Security Notice for CA Unified Infrastructure Management

Document created by Charles_Nack Employee on Nov 17, 2016Last modified by Melissa Potvin on Dec 17, 2016
Version 4Show Document
  • View in full screen mode

CA20161109-01: Security Notice for CA Unified Infrastructure Management 

 

CA20161109-01:  Security Notice for CA Unified Infrastructure Management

Issued:  November 09, 2016

CA Technologies Support is alerting customers to two vulnerabilities in CA Unified Infrastructure Management (formerly CA Nimsoft).  The first vulnerability, CVE-2016-9165, involves insecure handling of sessions IDs.  A remote attacker can potentially acquire a session ID and bypass authentication or elevate privileges.  The second vulnerability, CVE-2016-9164, is a path traversal information disclosure vulnerability associated with the diag.jsp file.  A remote attacker can potentially access sensitive information.  CA Technologies has assigned Medium and High risk ratings to these vulnerabilities.  Solutions are available.

Risk Rating

CVE-2016-9164 - Medium 
CVE-2016-9165 - Medium

Platform(s)

All

Affected Products

CA Unified Infrastructure Management 8.4 SP1 and earlier (formerly CA Nimsoft Monitor)
CA Unified Infrastructure Management Snap (formerly CA Nimsoft Monitor Snap)

How to determine if the installation is affected

Check the installed product version.

Solution

Upgrade to CA Unified Infrastructure Management r8.4 SP2 or later.  We recommend installing the latest release, CA Unified Infrastructure Management r8.47.

If you are unable to upgrade to CA Unified Infrastructure Management r8.47 at this time, you can alternatively upgrade to CA Unified Infrastructure Management r8.4 SP2.  To access r8.4 SP2, go to the Download Center at https://support.ca.com/, select product “CA Unified Infrastructure Mgmt Server Pack- On Prem – MULTI-PLATFORM“, and then select release “8.4”.  CA Unified Infrastructure Management r8.4 SP2 can then be found on the subsequent Product Download page.

Workaround

None

References

CVE-2016-9165 - CA UIM Session ID Vulnerability
CVE-2016-9164 - CA UIM diag.jsp Path Traversal Vulnerability

Acknowledgement

CVE-2016-9165 - rgod working with Trend Micro's Zero Day Initiative
CVE-2016-9164 - rgod working with Trend Micro's Zero Day Initiative

Change History

Version 1.0:  Initial Release, 2016-11-09

A notification about this security notice will be sent to customers who are subscribed to Proactive Notifications.

If additional information is required, please contact CA Technologies Support at https://support.ca.com/.

If you discover a vulnerability in CA Technologies products, please report your findings to the CA Technologies Product Vulnerability Response Team at vuln@ca.com.

CA Technologies Product Vulnerability Response Team PGP Key

Attachments

    Outcomes