Vulnerability Description
CA Identity Manager r12.6 to r12.6 SP8, 14.0, and 14.1 allows remote attackers to potentially identify passwords of locked accounts through an exhaustive search.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ca | Identity Manager | 12.6 |
| Ca | Identity Manager Virtual Appliance | 14.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/100956Third Party AdvisoryVDB Entry
- https://support.ca.com/us/product-content/recommended-reading/security-notices/cVendor Advisory
- http://www.securityfocus.com/bid/100956Third Party AdvisoryVDB Entry
- https://support.ca.com/us/product-content/recommended-reading/security-notices/cVendor Advisory
FAQ
What is CVE-2017-9393?
CVE-2017-9393 is a vulnerability with a CVSS score of 9.8 (CRITICAL). CA Identity Manager r12.6 to r12.6 SP8, 14.0, and 14.1 allows remote attackers to potentially identify passwords of locked accounts through an exhaustive search.
How severe is CVE-2017-9393?
CVE-2017-9393 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-9393?
Check the references section above for vendor advisories and patch information. Affected products include: Ca Identity Manager, Ca Identity Manager Virtual Appliance.