CA Service Desk Manager 14.1 / 17 Authentication Bypass

Discussion in 'News Aggregator' started by Packet Storm, 23 Jan 2019.

  1. Packet Storm

    Packet Storm Guest

    CA Technologies Support is alerting customers to multiple potential risks with CA Service Desk Manager. Multiple vulnerabilities exist that can allow a remote attacker to access sensitive information or possibly gain additional privileges. CA published solutions to address the vulnerabilities. The first vulnerability is due to how survey access is implemented. A malicious actor can access and submit survey information without authentication. The second vulnerability allows for a malicious actor to gain additional privileges. Versions affected include 14.1 and 17.

    Continue reading...
     

Share This Page

Loading...