CVE-2018-14597

CA Technologies Identity Governance 12.6, 14.0, 14.1, and 14.2 and CA Identity Suite Virtual Appliance 14.0, 14.1, and 14.2 provide telling error messages that may allow remote attackers to enumerate account names.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:broadcom:ca_identity_governance:*:*:*:*:*:*:*:*
cpe:2.3:a:broadcom:ca_identity_governance:12.6:*:*:*:*:*:*:*
cpe:2.3:a:broadcom:ca_identity_suite_virtual_appliance:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:49

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/105688 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/105688 - Third Party Advisory, VDB Entry
References () https://support.ca.com/us/product-content/recommended-reading/security-notices/ca20181017-01-security-notice-for-ca-identity-governance.html - Patch, Vendor Advisory () https://support.ca.com/us/product-content/recommended-reading/security-notices/ca20181017-01-security-notice-for-ca-identity-governance.html - Patch, Vendor Advisory

Information

Published : 2018-10-17 21:49

Updated : 2024-11-21 03:49


NVD link : CVE-2018-14597

Mitre link : CVE-2018-14597

CVE.ORG link : CVE-2018-14597


JSON object : View

Products Affected

broadcom

  • ca_identity_suite_virtual_appliance
  • ca_identity_governance
CWE
CWE-203

Observable Discrepancy

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor