PT-2018-12605 · Ca Technologies · Ca Identity Suite Virtual Appliance+1

Published

2018-10-17

·

Updated

2019-10-09

·

CVE-2018-14597

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions CA Technologies Identity Governance versions 12.6, 14.0, 14.1, and 14.2 CA Identity Suite Virtual Appliance versions 14.0, 14.1, and 14.2
Description The issue allows remote attackers to enumerate account names due to telling error messages provided by the software.
Recommendations For CA Technologies Identity Governance versions 12.6, 14.0, 14.1, and 14.2, consider modifying the error message handling to prevent information disclosure. For CA Identity Suite Virtual Appliance versions 14.0, 14.1, and 14.2, consider modifying the error message handling to prevent information disclosure. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-14597

Affected Products

Ca Identity Suite Virtual Appliance
Ca Technologies Identity Governance