PT-2016-3724 · Ca · Ca Single Sign-On
Publicado
2016-03-24
·
Atualizado
2021-04-09
·
CVE-2015-6854
CVSS v2.0
6.4
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
CA Single Sign-On versions R6, R12.0 before SP3 CR13, R12.0J before SP3 CR1.2, R12.5 before CR5
Description
The issue allows remote attackers to cause a denial of service or obtain sensitive information via a crafted request. This is related to the non-Domino web agents in CA Single Sign-On.
Recommendations
For version R6, update to a version later than R6 to resolve the issue.
For versions R12.0 before SP3 CR13, apply SP3 CR13 or later to resolve the issue.
For versions R12.0J before SP3 CR1.2, apply SP3 CR1.2 or later to resolve the issue.
For versions R12.5 before CR5, apply CR5 or later to resolve the issue.
Correção
Insufficient Verification of Data Authenticity
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ca Single Sign-On