CA Service Desk Manaager 12.9 / 14.1 Code Execution

CA Technologies Support is alerting customers to a vulnerability in CA Service Desk Manager (formerly CA Service Desk). A reflected cross site scripting vulnerability, CVE-2016-9148, exists in the QBE.EQ.REF_NUM parameter of the SDM web interface. A remote attacker, who can trick a user into clicking on or visiting a specially crafted link, could potentially execute arbitrary code on the targeted user’s system. CA Technologies has assigned a Medium risk rating to this vulnerability. A solution is available.

Leave a Reply