CVE-2016-5803: Ca Technologies Unified Infrastructure Management

High severity, CVSS 8.6. EPSS: 2.3% chance of exploitation in the next 30 days.

An issue was discovered in CA Unified Infrastructure Management Version 8.47 and earlier. The Unified Infrastructure Management software uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

Affected products

  • Ca Technologies Unified Infrastructure Management: up to and including 8.47

Published 2017-02-13. Last modified 2026-06-17.