CVE-2017-8391
MEDIUMCA Client Automation - Incorrect Permission Assignment
Title source: ruleDescription
The OS Installation Management component in CA Client Automation r12.9, r14.0, and r14.0 SP1 places an encrypted password into a readable local file during operating system installation, which allows local users to obtain sensitive information by reading this file after operating system installation.
References (3)
Scores
CVSS v3
5.5
EPSS
0.0005
EPSS Percentile
14.4%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-732
Status
draft
Affected Products (3)
ca/client_automation
ca/client_automation
ca/client_automation
Timeline
Published
May 06, 2017
Tracked Since
Feb 18, 2026