CVE-2017-9394: XSS
Published Nov 14, 2017
·Updated
A stored cross-site scripting vulnerability in CA Identity Governance 12.6 allows remote authenticated attackers to display HTML or execute script in the context of another user.
Affected Software
1 affected component
CA Identity Governance=12.6.0
Event History
Nov 14, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-9394?
CVE-2017-9394 is classified as a medium-severity vulnerability due to its potential for exploitation through stored cross-site scripting.
2
How do I fix CVE-2017-9394?
To fix CVE-2017-9394, upgrade CA Identity Governance to the latest version that addresses this vulnerability.
3
Who is affected by CVE-2017-9394?
CVE-2017-9394 affects users of CA Identity Governance version 12.6.0.
4
What type of vulnerability is CVE-2017-9394?
CVE-2017-9394 is a stored cross-site scripting (XSS) vulnerability that allows attackers to execute scripts in the context of another user.
5
Can CVE-2017-9394 lead to data theft?
Yes, CVE-2017-9394 can potentially be utilized for data theft by executing malicious scripts against affected users.