Unauthorized Password Reset Vulnerability in BMC BladeLogic Server Automation
CVE-2016-1543
What is CVE-2016-1543?
The RPC API in the RSCD agent of BMC BladeLogic Server Automation versions 8.2.x through 8.7.x on Linux and UNIX platforms is susceptible to an issue where remote attackers can exploit authorization bypass vulnerabilities. By sending specially crafted action packets to the XML-RPC interface after an authorization failure, attackers may reset arbitrary user passwords, thereby compromising system integrity and security. It is crucial for users of affected versions to implement mitigations and apply patches promptly to safeguard their environments.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
EPSS Score
73% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
