9.8
CVE-2017-9393
- EPSS 1.68%
- Veröffentlicht 22.09.2017 14:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
- Erkennungen
CA Identity Manager r12.6 to r12.6 SP8, 14.0, and 14.1 allows remote attackers to potentially identify passwords of locked accounts through an exhaustive search.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ca ≫ Identity Manager Version 12.6 Update ga
Ca ≫ Identity Manager Version 12.6 Update sp1
Ca ≫ Identity Manager Version 12.6 Update sp2
Ca ≫ Identity Manager Version 12.6 Update sp3
Ca ≫ Identity Manager Version 12.6 Update sp4
Ca ≫ Identity Manager Version 12.6 Update sp5
Ca ≫ Identity Manager Version 12.6 Update sp6
Ca ≫ Identity Manager Version 12.6 Update sp7
Ca ≫ Identity Manager Version 12.6 Update sp8
Ca ≫ Identity Manager Version 14.0
Ca ≫ Identity Manager Version 14.1
Ca ≫ Identity Manager Virtual Appliance Version 14.0
Ca ≫ Identity Manager Virtual Appliance Version 14.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.68% | 0.74 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.8 | 3.9 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
http://www.securityfocus.com/bid/100956
https://support.ca.com/us/product-content/recommended-reading/security-notices/ca20170921-01--security-notice-for-ca-identity-manager.html