Junglewise Threat Intelligence

CVE-2016-10086: CA Service Desk Manager incorrect permissions in RESTful web services

CVE-2016-10086 · Severity: high · CVSS 8.1 · Published 2017-01-18

Technologies: Microsoft Windows, IBM Aix, Oracle Solaris, Linux Kernel. Vendors: Microsoft, IBM, Oracle, Linux.

Executive brief

CA Service Desk Manager, a platform used by organizations to manage IT support tickets and service requests, contains a security flaw in its web services. An authorized user with low-level access could exploit this vulnerability to view or change sensitive task information they should not be able to see. This could lead to unauthorized data disclosure or the disruption of internal IT workflows and service management processes.

Technical details

An improper access control vulnerability (CWE-264) exists in the RESTful web services component of CA Service Desk Manager. The root cause is the application of incorrect permissions during the processing of RESTful requests, which fails to properly restrict access to task-related data. A remote attacker with valid, low-privileged credentials can send crafted REST API requests to view or modify task information beyond their authorized scope. This vulnerability affects versions 12.9 and 14.1 across multiple operating systems including Windows, Linux, AIX, and Solaris. CA Technologies has released patches to address this issue.

Affected products

  • CA Technologies Service Desk Manager 12.9
  • CA Technologies Service Desk Management 14.1

Timeline

  • 2017-01-09: advisory: Vendor security notice released by CA Technologies
  • 2017-01-18: disclosed: NVD publication date

References

Related threats