First published: Wed Oct 17 2018(Updated: )
CA Technologies Identity Governance 12.6, 14.0, 14.1, and 14.2 and CA Identity Suite Virtual Appliance 14.0, 14.1, and 14.2 provide telling error messages that may allow remote attackers to enumerate account names.
Credit: vuln@ca.com
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom CA Identity Governance | >=14.0<=14.2 | |
Broadcom CA Identity Governance | =12.6 | |
Broadcom CA Identity Suite Virtual Appliance | >=14.0<=14.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-14597 is classified as a medium severity vulnerability that may allow remote attackers to enumerate account names.
To mitigate CVE-2018-14597, upgrading to the latest version of CA Identity Governance or CA Identity Suite Virtual Appliance is recommended.
CVE-2018-14597 affects CA Identity Governance versions 12.6, 14.0, 14.1, and 14.2 and CA Identity Suite Virtual Appliance versions 14.0, 14.1, and 14.2.
CVE-2018-14597 can potentially lead to unauthorized access by enabling attackers to gather account names through error messages.
There are no specific workarounds mentioned for CVE-2018-14597; the best course of action is to apply available updates.