PT-2020-12752 · Ca · Ca Api Developer Portal

Matteo Civera

·

Published

2020-04-15

·

Updated

2020-04-20

·

CVE-2020-11658

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CA API Developer Portal versions 4.3.1 and earlier
Description The issue allows attackers to bypass authorization due to the insecure handling of shared secret keys.
Recommendations For CA API Developer Portal versions 4.3.1 and earlier, update to a version that properly secures shared secret keys to prevent authorization bypass.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-11658

Affected Products

Ca Api Developer Portal