PT-2018-12605 · Ca Technologies · Ca Identity Suite Virtual Appliance+1

Publicado

2018-10-17

·

Atualizado

2019-10-09

·

CVE-2018-14597

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions CA Technologies Identity Governance versions 12.6, 14.0, 14.1, and 14.2 CA Identity Suite Virtual Appliance versions 14.0, 14.1, and 14.2
Description The issue allows remote attackers to enumerate account names due to telling error messages provided by the software.
Recommendations For CA Technologies Identity Governance versions 12.6, 14.0, 14.1, and 14.2, consider modifying the error message handling to prevent information disclosure. For CA Identity Suite Virtual Appliance versions 14.0, 14.1, and 14.2, consider modifying the error message handling to prevent information disclosure. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Side Channel Attack

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-14597

Produtos afetados

Ca Identity Suite Virtual Appliance
Ca Technologies Identity Governance