CVE-2017-9393

CA Identity Manager r12.6 to r12.6 SP8, 14.0, and 14.1 allows remote attackers to potentially identify passwords of locked accounts through an exhaustive search.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
caCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 60%
VendorProductVersion
caidentity_manager
12.6:ga
caidentity_manager
12.6:sp1
caidentity_manager
12.6:sp2
caidentity_manager
12.6:sp3
caidentity_manager
12.6:sp4
caidentity_manager
12.6:sp5
caidentity_manager
12.6:sp6
caidentity_manager
12.6:sp7
caidentity_manager
12.6:sp8
caidentity_manager
14.0
caidentity_manager
14.1
caidentity_manager_virtual_appliance
14.0
caidentity_manager_virtual_appliance
14.1
𝑥
= Vulnerable software versions