First published: Wed Aug 29 2018(Updated: )
A hardcoded secret key, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows attackers to access sensitive information.
Credit: vuln@ca.com
Affected Software | Affected Version | How to fix |
---|---|---|
EMC Unified Infrastructure Manager | =8.4.7 | |
EMC Unified Infrastructure Manager | =8.5 | |
EMC Unified Infrastructure Manager | =8.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-13819 is considered a high severity vulnerability due to the presence of a hardcoded secret key that can be exploited.
To mitigate CVE-2018-13819, update to the latest versions of CA Unified Infrastructure Management that remove the hardcoded secret key.
CVE-2018-13819 affects versions 8.4.7, 8.5, and 8.5.1 of CA Unified Infrastructure Management.
Exploitation of CVE-2018-13819 can allow attackers to access sensitive information within the affected CA Unified Infrastructure Management systems.
Currently, there is no known effective workaround for CVE-2018-13819; upgrading is strongly recommended for security.