-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 CA20161109-01: Security Notice for CA Unified Infrastructure Management Issued: November 09, 2016 CA Technologies Support is alerting customers to three vulnerabilities in CA Unified Infrastructure Management (formerly CA Nimsoft). The first vulnerability, CVE-2016-9165, involves insecure handling of sessions IDs. A remote attacker can potentially acquire a session ID and bypass authentication or elevate privileges. The second vulnerability, CVE-2016-9164, is a path traversal information disclosure vulnerability associated with the diag.jsp file. A remote attacker can potentially access sensitive information. The third vulnerability, CVE-2016-5803, is a path traversal information disclosure vulnerability associated with the download_lar.jsp file. A remote attacker can potentially access sensitive information. CA Technologies has assigned Medium and High risk ratings to these vulnerabilities. Solutions are available. Risk Rating CVE-2016-9164 - Medium CVE-2016-9165 - Medium CVE-2016-5803 - High Platform(s) All Affected Products CA Unified Infrastructure Management 8.4 SP1 and earlier (formerly CA Nimsoft Monitor) CA Unified Infrastructure Management Snap (formerly CA Nimsoft Monitor Snap) How to determine if the installation is affected Check the installed product version. Solution Upgrade to CA Unified Infrastructure Management r8.4 SP2 or later. We recommend installing the latest release, CA Unified Infrastructure Management r8.47. If you are unable to upgrade to CA Unified Infrastructure Management r8.47 at this time, you can alternatively upgrade to CA Unified Infrastructure Management r8.4 SP2. To access r8.4 SP2, go to the Download Center at https://support.ca.com/, select product "CA Unified Infrastructure Mgmt Server Pack- On Prem - MULTI-PLATFORM", and then select release "8.4". CA Unified Infrastructure Management r8.4 SP2 can then be found on the subsequent Product Download page. Workaround None References CVE-2016-9165 - CA UIM Session ID Vulnerability CVE-2016-9164 - CA UIM diag.jsp Path Traversal Vulnerability CVE-2016-5803 - CA UIM download_lar.jsp Path Traversal Vulnerability Acknowledgement CVE-2016-9165 - rgod working with Trend Micro's Zero Day Initiative CVE-2016-9164 - rgod working with Trend Micro's Zero Day Initiative CVE-2016-5803 - rgod working with Trend Micro's Zero Day Initiative Change History Version 1.0: Initial Release, 2016-11-09 If additional information is required, please contact CA Technologies Support at https://support.ca.com/ If you discover a vulnerability in CA Technologies products, please report your findings to the CA Technologies Product Vulnerability Response Team at vuln ca.com CA Technologies Security Notices can be found at https://support.ca.com/ CA Product Vulnerability Response Team PGP Key: https://www.ca.com/us/support/ca-support-online/documents.aspx?id=177782 Regards, Ken Williams Vulnerability Response Director, CA Product Vulnerability Response Team Copyright (c) 2016 CA. All Rights Reserved. 520 Madison Avenue, 22nd Floor, New York, NY 10022. All other trademarks, trade names, service marks, and logos referenced herein belong to their respective companies. -----BEGIN PGP SIGNATURE----- Version: Encryption Desktop 10.3.2 (Build 16620) Charset: utf-8 wsFVAwUBWCO8yzuotw2cX+zOAQqDuhAAgSxI5amAsDgEmSdYvzsWHCuCr9SJ8Kgz KuFWAkQoLa7pPft8Y5M4iaGDkxmVnT9QzXJtZKn0bGUiPDh6McxD7dyOxZtSPkVc 4uEvPGWSOBLqn1/Gl4wP5uLumWe9wzSN5CvHA7udDflQfyeD5RqljEaQwfCWT7IX EebuzD+E51Bl/OmRiEtc1/gLuZ/ATq6RaL5jI+hRtg6IVjIM3YdbWSEr0jXqPQyE qdYRYcKIuPqxs9eZJ2rW+wFFGrsuAeeOBdBcfQmyoe2T9GzDgokuDWGesdtJOGWu SR2TRdt2BoRtu1E+qIcAnZAav/NXgGSLbXvVPWh8Dc6xRQFAxBkGTr0PkDwHjASI gN7YMGGfZRAzMYSElJxXnf9S2IqBJjRmbxx7sMWOBOqA0/Pnv1OZ5FfNrYbH1Bye b9N1nU3SaDYky4R8mWh7TOnk9I91wLg6YmEZNhfk6sMnq49WPz1cWFISBuj+gI2z 0TYk0LX9g6wW12uNS8KdynvcBTeHi527cvV5ThoGKfT6BoY3BwX3LFnM++nA2vtI rhwgDyJ9lxgqR8lEFKZQBJanSRYR9Zb+bhuSRBsaYo/ZesApWpdGg0LlsJcLKfXe VJbrr8sP0BGLrukm4lNt20EiusOLazZ6ObikLjDbJiQjhBALcvOr1Lsd2JE+dGJG NnQWLayjcHI= =DjVa -----END PGP SIGNATURE-----