CVE-2019-7393

A UI redress vulnerability in the administrative user interface of CA Technologies CA Strong Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 7.1.x and CA Risk Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 3.1.x may allow a remote attacker to gain sensitive information in some cases.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ca:risk_authentication:*:*:*:*:*:*:*:*
cpe:2.3:a:ca:risk_authentication:3.1:*:*:*:*:*:*:*
cpe:2.3:a:ca:risk_authentication:9.0:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:ca:strong_authentication:*:*:*:*:*:*:*:*
cpe:2.3:a:ca:strong_authentication:7.1:*:*:*:*:*:*:*
cpe:2.3:a:ca:strong_authentication:9.0:*:*:*:*:*:*:*

History

21 Nov 2024, 04:48

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/153089/CA-Risk-Strong-Authentication-Privilege-Escalation.html - Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/153089/CA-Risk-Strong-Authentication-Privilege-Escalation.html - Third Party Advisory, VDB Entry
References () http://seclists.org/fulldisclosure/2019/May/43 - Mailing List, Third Party Advisory () http://seclists.org/fulldisclosure/2019/May/43 - Mailing List, Third Party Advisory
References () http://www.securityfocus.com/bid/108483 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/108483 - Third Party Advisory, VDB Entry
References () https://seclists.org/bugtraq/2019/May/66 - Mailing List, Third Party Advisory () https://seclists.org/bugtraq/2019/May/66 - Mailing List, Third Party Advisory
References () https://support.ca.com/us/product-content/recommended-reading/security-notices/CA20190523-01--security-notice-for-ca-risk-authentication-and-ca-strong-authentication.html - Vendor Advisory () https://support.ca.com/us/product-content/recommended-reading/security-notices/CA20190523-01--security-notice-for-ca-risk-authentication-and-ca-strong-authentication.html - Vendor Advisory

Information

Published : 2019-05-28 19:29

Updated : 2024-11-21 04:48


NVD link : CVE-2019-7393

Mitre link : CVE-2019-7393

CVE.ORG link : CVE-2019-7393


JSON object : View

Products Affected

ca

  • risk_authentication
  • strong_authentication
CWE
CWE-1021

Improper Restriction of Rendered UI Layers or Frames