First published: Tue Nov 14 2017(Updated: )
A stored cross-site scripting vulnerability in CA Identity Governance 12.6 allows remote authenticated attackers to display HTML or execute script in the context of another user.
Credit: vuln@ca.com
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom CA Identity Governance | =12.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9394 is classified as a medium-severity vulnerability due to its potential for exploitation through stored cross-site scripting.
To fix CVE-2017-9394, upgrade CA Identity Governance to the latest version that addresses this vulnerability.
CVE-2017-9394 affects users of CA Identity Governance version 12.6.0.
CVE-2017-9394 is a stored cross-site scripting (XSS) vulnerability that allows attackers to execute scripts in the context of another user.
Yes, CVE-2017-9394 can potentially be utilized for data theft by executing malicious scripts against affected users.