SB2012122601 - Multiple vulnerabilities in CA IdentityMinder
Published: December 26, 2012 Updated: August 11, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Input validation error (CVE-ID: CVE-2012-6299)
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
Unspecified vulnerability in CA IdentityMinder r12.0 through CR16, r12.5 before SP15, and r12.6 GA allows remote attackers to bypass intended access restrictions via unknown vectors.
2) Input validation error (CVE-ID: CVE-2012-6298)
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
Unspecified vulnerability in CA IdentityMinder r12.0 through CR16, r12.5 before SP15, and r12.6 GA allows remote attackers to execute arbitrary commands or modify data via unknown vectors.
Remediation
Install update from vendor's website.