CA Identity Governance Username Enumeration

Discussion in 'News Aggregator' started by Packet Storm, 20 Oct 2018.

  1. Packet Storm

    Packet Storm Guest

    CA Technologies Support is alerting customers to a low risk issue with CA Identity Governance. In a certain product configuration, an attacker can gain sensitive information. CA published solutions to address the vulnerability. The vulnerability occurs due to how CA Identity Governance responds to login requests. An attacker may exploit the vulnerability to enumerate account names. Affected products include CA Identity Suite Virtual Appliance 14.0, 14.1, and 14.2 and CA Identity Governance 12.6, 14.0, 14.1, and 14.2.

    Continue reading...
     

Share This Page

Loading...