« Volver al listado

CVE-2017-9393

Estado: ModificadaCrítica (9.8)—

CA Identity Manager r12.6 to r12.6 SP8, 14.0, and 14.1 allows remote attackers to potentially identify passwords of locked accounts through an exhaustive search.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-9393",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": true,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "vuln@ca.com",
      "affectedData": [
        {
          "vendor": "CA Technologies",
          "product": "Identity Manager",
          "versions": [
            {
              "status": "affected",
              "version": "12.6 through 12.6 SP8"
            },
            {
              "status": "affected",
              "version": "14.0"
            },
            {
              "status": "affected",
              "version": "14.1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-09-22T14:29:00.273",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/100956",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "vuln@ca.com"
    },
    {
      "url": "https://support.ca.com/us/product-content/recommended-reading/security-notices/ca20170921-01--security-notice-for-ca-identity-manager.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "vuln@ca.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/100956",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.ca.com/us/product-content/recommended-reading/security-notices/ca20170921-01--security-notice-for-ca-identity-manager.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "CA Identity Manager r12.6 to r12.6 SP8, 14.0, and 14.1 allows remote attackers to potentially identify passwords of locked accounts through an exhaustive search."
    },
    {
      "lang": "es",
      "value": "CA Identity Manager de la versión r12.6 a la r12.6 SP8, 14.0 y 14.1 permite que los atacantes remotos identifiquen contraseñas de cuentas bloqueadas mediante una búsqueda exhaustiva."
    }
  ],
  "lastModified": "2026-06-17T01:28:01.903",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ca:identity_manager:12.6:ga:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BC40E880-CBE1-401D-AC52-ABD8AA5BA532"
            },
            {
              "criteria": "cpe:2.3:a:ca:identity_manager:12.6:sp1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "29BC5F88-A884-4F5E-9D04-34C73B7A2CB5"
            },
            {
              "criteria": "cpe:2.3:a:ca:identity_manager:12.6:sp2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "18C26D26-5ACC-489E-88BA-25A0008CA2F3"
            },
            {
              "criteria": "cpe:2.3:a:ca:identity_manager:12.6:sp3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FC189A1D-4508-466A-9116-99EF52A2BB17"
            },
            {
              "criteria": "cpe:2.3:a:ca:identity_manager:12.6:sp4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "73F4AC0A-5F43-4000-A414-99964CB404CD"
            },
            {
              "criteria": "cpe:2.3:a:ca:identity_manager:12.6:sp5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3478DC20-8307-4DA8-B922-5A995BDE233C"
            },
            {
              "criteria": "cpe:2.3:a:ca:identity_manager:12.6:sp6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "97628548-6314-4A4F-AA5B-7FCCBA168150"
            },
            {
              "criteria": "cpe:2.3:a:ca:identity_manager:12.6:sp7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BD363ACE-7E26-430B-AA6A-1AE1BF4C5142"
            },
            {
              "criteria": "cpe:2.3:a:ca:identity_manager:12.6:sp8:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CC53B461-E09D-45C3-8CB8-CEAA69FF6A4E"
            },
            {
              "criteria": "cpe:2.3:a:ca:identity_manager:14.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FDB09257-D88D-417A-B734-7AF24889D46B"
            },
            {
              "criteria": "cpe:2.3:a:ca:identity_manager:14.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D2D6060C-BF65-45E3-91F5-D3AAC4305ACC"
            },
            {
              "criteria": "cpe:2.3:a:ca:identity_manager_virtual_appliance:14.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C494D3D0-0351-40BC-AA45-54F1272250A8"
            },
            {
              "criteria": "cpe:2.3:a:ca:identity_manager_virtual_appliance:14.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "416D96F6-1BB4-4F0C-A75C-0E88968FC0B7"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "vuln@ca.com"
}