PT-2019-18577 · Ca · Ca Strong Authentication+1
Rohit Yadav
·
Published
2019-05-28
·
Updated
2020-10-06
·
CVE-2019-7393
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
CA Strong Authentication versions 7.1.x through 9.0.x
CA Strong Authentication version 8.0.x
CA Strong Authentication version 8.1.x
CA Strong Authentication version 8.2.x
CA Risk Authentication versions 3.1.x through 9.0.x
CA Risk Authentication version 8.0.x
CA Risk Authentication version 8.1.x
CA Risk Authentication version 8.2.x
Description
A UI redress issue in the administrative user interface may allow a remote attacker to gain sensitive information in some cases.
Recommendations
For CA Strong Authentication versions 7.1.x through 9.0.x, consider restricting access to the administrative user interface until a fix is available.
For CA Strong Authentication version 8.0.x, version 8.1.x, and version 8.2.x, restrict access to the administrative user interface as a temporary workaround.
For CA Risk Authentication versions 3.1.x through 9.0.x, restrict access to the administrative user interface to minimize the risk of exploitation.
For CA Risk Authentication version 8.0.x, version 8.1.x, and version 8.2.x, consider disabling access to the administrative user interface until a patch is available.
Fix
Clickjacking
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ca Risk Authentication
Ca Strong Authentication