CVE-2020-11661
Description
CA API Developer Portal 4.3.1 and earlier contains an access control flaw that allows privileged users to view and edit user data.
References
Vendor Advisory
Third Party AdvisoryVDB Entry
Mailing ListThird Party Advisory
Third Party AdvisoryVDB Entry
CvssV3 impact
Version | 3.1 |
VectorString | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
AttackVector | NETWORK |
AttackComplexity | LOW |
PrivilegesRequired | LOW |
UserInteraction | NONE |
Scope | UNCHANGED |
ConfidentialityImpact | HIGH |
IntegrityImpact | HIGH |
AvailabilityImpact | NONE |
BaseScore | 8.1 |
BaseSeverity | HIGH |
CvssV2 impact
Version | 2.0 |
VectorString | AV:N/AC:L/Au:S/C:P/I:P/A:N |
AccessVector | NETWORK |
AccessComplexity | LOW |
Authentication | SINGLE |
ConfidentialityImpact | PARTIAL |
IntegrityImpact | PARTIAL |
AvailabilityImpact | NONE |
BaseScore | 5.5 |