PT-2019-18577 · Ca · Ca Strong Authentication+1

Rohit Yadav

·

Publicado

2019-05-28

·

Atualizado

2020-10-06

·

CVE-2019-7393

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions CA Strong Authentication versions 7.1.x through 9.0.x CA Strong Authentication version 8.0.x CA Strong Authentication version 8.1.x CA Strong Authentication version 8.2.x CA Risk Authentication versions 3.1.x through 9.0.x CA Risk Authentication version 8.0.x CA Risk Authentication version 8.1.x CA Risk Authentication version 8.2.x
Description A UI redress issue in the administrative user interface may allow a remote attacker to gain sensitive information in some cases.
Recommendations For CA Strong Authentication versions 7.1.x through 9.0.x, consider restricting access to the administrative user interface until a fix is available. For CA Strong Authentication version 8.0.x, version 8.1.x, and version 8.2.x, restrict access to the administrative user interface as a temporary workaround. For CA Risk Authentication versions 3.1.x through 9.0.x, restrict access to the administrative user interface to minimize the risk of exploitation. For CA Risk Authentication version 8.0.x, version 8.1.x, and version 8.2.x, consider disabling access to the administrative user interface until a patch is available.

Correção

Clickjacking

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-7393

Produtos afetados

Ca Risk Authentication
Ca Strong Authentication