PT-2004-2603 · Ca · Ca Unicenter Management Portal

Thomas Adams

·

Published

2004-09-21

·

Updated

2017-07-11

·

CVE-2004-1697

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions CA Unicenter Management Portal versions 2.0 through 3.1
Description The issue concerns the "Forgot your Password" link, which displays different error messages for existing and non-existing users. This could allow remote attackers to guess valid usernames.
Recommendations For CA Unicenter Management Portal versions 2.0 through 3.1, consider modifying the error messages displayed by the "Forgot your Password" link to be generic, avoiding the disclosure of username existence. As a temporary workaround, restrict access to the "Forgot your Password" link until a more permanent solution is implemented.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-1697

Affected Products

Ca Unicenter Management Portal