First published: Wed Apr 15 2020(Updated: )
CA API Developer Portal 4.3.1 and earlier handles 404 requests in an insecure manner, which allows attackers to perform open redirect attacks.
Credit: vuln@ca.com
Affected Software | Affected Version | How to fix |
---|---|---|
CA API Developer Portal | >=4.0<=4.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-11663 is classified as a medium severity vulnerability due to its potential for open redirect attacks.
To fix CVE-2020-11663, upgrade CA API Developer Portal to version 4.3.2 or later.
Attackers can exploit CVE-2020-11663 to perform open redirect attacks which may lead to phishing or unwanted redirection.
CVE-2020-11663 affects CA API Developer Portal versions 4.3.1 and earlier.
CVE-2020-11663 exploits the insecure handling of 404 requests in CA API Developer Portal.