Executive brief
A vulnerability in the CA Common Services component, used across several CA enterprise management products, allows a local user to modify system files. This component is responsible for managing background services on Unix-based systems like Linux and AIX. An attacker with basic access to a system could exploit this flaw to gain full administrative (root) control, potentially leading to complete system takeover and data theft.
Technical details
The vulnerability exists within the 'casrvc' program, a component of CA Common Services used for service management. It is classified as an improper input validation flaw (CWE-20). A local attacker with low privileges can exploit insufficient validation within the program to modify arbitrary files on the filesystem. By targeting sensitive system files, the attacker can escalate their privileges to root. The issue affects multiple CA products running on AIX, HP-UX, Linux, and Solaris platforms. CA Technologies released a security notice (CA20170126-01) to address the issue.
Affected products
- CA Technologies Client Automation 12.8, 12.9, 14.0
- CA Technologies SystemEDGE 5.8.2, 5.9
- CA Technologies Systems Performance for Infrastructure Managers 12.8, 12.9
- CA Technologies Universal Job Management Agent 11.2
- CA Technologies Virtual Assurance for Infrastructure Managers 12.8, 12.9
- CA Technologies Workload Automation AE 11, 11.3, 11.3.5, 11.3.6
Timeline
- 2017-01-26: advisory: CA Technologies security notice CA20170126-01 released
- 2017-01-27: disclosed: NVD publication date
References
- http://www.securityfocus.com/archive/1/540062/100/0/threaded
- http://www.securityfocus.com/bid/95819
- http://www.securitytracker.com/id/1037730
- https://www.ca.com/us/services-support/ca-support/ca-support-online/product-content/recommended-reading/security-notices/ca20170126-01--security-notice-for-ca-common-services-casrvc.html