CVE-2017-8391

MEDIUM

CA Client Automation - Incorrect Permission Assignment

Title source: rule

Description

The OS Installation Management component in CA Client Automation r12.9, r14.0, and r14.0 SP1 places an encrypted password into a readable local file during operating system installation, which allows local users to obtain sensitive information by reading this file after operating system installation.

Scores

CVSS v3 5.5
EPSS 0.0005
EPSS Percentile 14.4%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-732
Status draft

Affected Products (3)

ca/client_automation
ca/client_automation
ca/client_automation

Timeline

Published May 06, 2017
Tracked Since Feb 18, 2026