CVE-2019-7394

HIGH

CA Technologies CA Strong Authentication <9.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

A privilege escalation vulnerability in the administrative user interface of CA Technologies CA Strong Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 7.1.x and CA Risk Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 3.1.x allows an authenticated attacker to gain additional privileges in some cases where an account has customized and limited privileges.

References (5)

Core 5
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_bugtraq
https://seclists.org/bugtraq/2019/May/66
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/108483
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2019/May/43

Scores

CVSS v3 8.8
EPSS 0.0287
EPSS Percentile 85.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-269
Status published
Products (6)
ca/risk_authentication 3.1
ca/risk_authentication 9.0
ca/risk_authentication 8.0 - 8.2.1
ca/strong_authentication 7.1
ca/strong_authentication 9.0
ca/strong_authentication 8.0 - 8.2.1
Published May 28, 2019
Tracked Since Feb 18, 2026