CVE-2017-9393: Ca Identity Manager
Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.
CA Identity Manager r12.6 to r12.6 SP8, 14.0, and 14.1 allows remote attackers to potentially identify passwords of locked accounts through an exhaustive search.
Affected products
- Ca Identity Manager: version 12.6 only; version 14.0 only; version 14.1 only
- Ca Identity Manager Virtual Appliance: version 14.0 only; version 14.1 only
Published 2017-09-22. Last modified 2026-06-17.