First published: Fri Sep 22 2017(Updated: )
CA Identity Manager r12.6 to r12.6 SP8, 14.0, and 14.1 allows remote attackers to potentially identify passwords of locked accounts through an exhaustive search.
Credit: vuln@ca.com
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom CA IdentityMinder | =12.6-ga | |
Broadcom CA IdentityMinder | =12.6-sp1 | |
Broadcom CA IdentityMinder | =12.6-sp2 | |
Broadcom CA IdentityMinder | =12.6-sp3 | |
Broadcom CA IdentityMinder | =12.6-sp4 | |
Broadcom CA IdentityMinder | =12.6-sp5 | |
Broadcom CA IdentityMinder | =12.6-sp6 | |
Broadcom CA IdentityMinder | =12.6-sp7 | |
Broadcom CA IdentityMinder | =12.6-sp8 | |
Broadcom CA IdentityMinder | =14.0 | |
Broadcom CA IdentityMinder | =14.1 | |
CA Identity Manager Virtual Appliance | =14.0 | |
CA Identity Manager Virtual Appliance | =14.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9393 is classified as a medium severity vulnerability that allows remote attackers to potentially discover passwords of locked accounts.
To fix CVE-2017-9393, you should upgrade CA Identity Manager to the latest version or apply available patches provided by the vendor.
CVE-2017-9393 affects CA Identity Manager versions 12.6 to 12.6 SP8, 14.0, and 14.1.
Yes, CVE-2017-9393 can be exploited by remote attackers who can perform exhaustive searches on locked accounts.
CVE-2017-9393 is associated with a brute force attack method targeting locked accounts to potentially reveal passwords.