First published: Tue Nov 04 2014(Updated: )
CA Cloud Service Management (CSM) before Summer 2014 does not properly verify authentication tokens from an Identity Provider, which allows user-assisted remote attackers to bypass intended access restrictions via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CA Cloud Service Management | <=2014 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8472 is considered a high severity vulnerability due to its potential to allow unauthorized access.
To mitigate CVE-2014-8472, update your CA Cloud Service Management to a version released after the Summer 2014 patch.
CVE-2014-8472 can allow attackers to bypass access restrictions, leading to unauthorized actions by authenticated users.
CVE-2014-8472 affects users of CA Cloud Service Management versions prior to Summer 2014.
There are no official workarounds for CVE-2014-8472; upgrading to a patched version is the recommended action.