CVE-2004-1697: High severity CA Unicenter Management vulnerability
The "Forgot your Password" link in Computer Associates (CA) Unicenter Management Portal 2.0 and 3.1 displays different error messages for users that exist and users that do not exist, which could allow remote attackers to guess valid usernames.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1697?
CVE-2004-1697 is considered a medium severity vulnerability due to its potential for user enumeration attacks.
How do I fix CVE-2004-1697?
To fix CVE-2004-1697, update to the latest version of CA Unicenter Management Portal that addresses this vulnerability.
Which versions of CA Unicenter Management are affected by CVE-2004-1697?
CVE-2004-1697 affects CA Unicenter Management Portal versions 2.0 and 3.1.
What kind of attack does CVE-2004-1697 facilitate?
CVE-2004-1697 facilitates remote attackers to guess valid usernames through differing error messages.
Is there a workaround for CVE-2004-1697?
Currently, there are no known workarounds for CVE-2004-1697 other than applying the appropriate security updates.