CVE-2016-9795 is a local privilege escalation vulnerability affecting various CA Common Services products, including CA Client Automation, SystemEDGE, and Workload Automation AE, across AIX, HP-UX, Linux, and Solaris operating systems. The vulnerability stems from insufficient validation in the casrvc program, allowing local users to modify arbitrary files and gain root privileges. With a CVSS score of 7.8 (HIGH), it has a low attack complexity and requires local access, but can lead to full compromise of confidentiality, integrity, and availability. There is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.0CPE matchmatch criteria | cpe:2.3:a:broadcom:ca_workload_automation_ae:11.0:*:*:*:*:*:*:* | ||
11.3CPE matchmatch criteria | cpe:2.3:a:broadcom:ca_workload_automation_ae:11.3:*:*:*:*:*:*:* | ||
11.3.5CPE matchmatch criteria | cpe:2.3:a:broadcom:ca_workload_automation_ae:11.3.5:*:*:*:*:*:*:* | ||
11.3.6CPE matchmatch criteria | cpe:2.3:a:broadcom:ca_workload_automation_ae:11.3.6:*:*:*:*:*:*:* | ||
12.8CPE matchmatch criteria | cpe:2.3:a:broadcom:client_automation:12.8:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2016-9795
Mar 14, 2023CVE-2016-9795
Apr 13, 2021The casrvc program in CA Common Services as used in CA Client Automation 12.8 12.9 and 14.0; CA SystemEDGE 5.8.2 and 5.9; CA Systems Performance for Infrastructure Managers 12.8 and 12.9; CA Universal Job Management Agent 11.2; CA Virtual Assurance for Infrastructure Managers 12.8 and 12.9; CA Workload Automation AE 11 11.3 11.3.5 and 11.3.6 on AIX HP-UX Linux and Solaris allows local users to modify arbitrary files and consequently gain root privileges via vectors related to insufficient validation.
Jan 10, 2017