CVE-2016-4322: Bmc Bladelogic Server Automation Console

Critical severity, CVSS 9.8. EPSS: 5.2% chance of exploitation in the next 30 days.

BMC BladeLogic Server Automation (BSA) before 8.7 Patch 3 allows remote attackers to bypass authentication and consequently read arbitrary files or possibly have unspecified other impact by leveraging a "logic flaw" in the authentication process.

Affected products

  • Bmc Bladelogic Server Automation Console: version 8.7.00 only

Published 2016-12-13. Last modified 2026-06-17.