CVE-2017-9394
MEDIUMCA Identity Governance 12.6 - XSS
Title source: llmDescription
A stored cross-site scripting vulnerability in CA Identity Governance 12.6 allows remote authenticated attackers to display HTML or execute script in the context of another user.
Scores
CVSS v3
5.4
EPSS
0.0018
EPSS Percentile
39.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Classification
CWE
CWE-79
Status
draft
Affected Products (1)
ca/identity_governance
Timeline
Published
Nov 14, 2017
Tracked Since
Feb 18, 2026