'; } else{ echo ''; } echo '
|
|
|||
Release Date:2025/9/15
Rule Name:CVE-2016-5803: CA Unified Infrastructure Management download_lar.jsp Directory Traversal Vulnerability
Severity:high
CVE ID:CVE-2016-5803
| Descripiton:
|
A directory traversal vulnerability exists in CA Unified Infrastructure Management. The vulnerability is due to insufficient input validation while processing HTTP requests sent to the download_lar.jsp. A remote unauthenticated attacker can exploit this vulnerability by sending a malicious request to the vulnerable server. Successful exploitation results in arbitrary file download from the target server. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
| Solution:
|
Update vendor patches.