BMC Server Automation (BSA) RSCD Agent User Enumeration

Discussion in 'News Aggregator' started by Packet Storm, 29 Mar 2016.

  1. Packet Storm

    Packet Storm Guest

    A security vulnerability has been identified in BMC Server Automation (BSA) RSCD Agent on the Linux/Unix platforms. The vulnerability allows unauthorized remote user enumeration on a target server by using the Remote Procedure Call (RPC) API of the RSCD Agent. Windows agents are not affected. The flaw has been confirmed to exist in the following versions of BSA on Unix and Linux platforms: 8.2.x, 8.3.x, 8.5.x, 8.6.x and 8.7.x.

    Continue reading...
     

Share This Page

Loading...