CVE-2018-14597: Broadcom Ca Identity Governance

Medium severity, CVSS 5.3. EPSS: 1.3% chance of exploitation in the next 30 days.

CA Technologies Identity Governance 12.6, 14.0, 14.1, and 14.2 and CA Identity Suite Virtual Appliance 14.0, 14.1, and 14.2 provide telling error messages that may allow remote attackers to enumerate account names.

Affected products

  • Broadcom Ca Identity Governance: from 14.0, up to and including 14.2; version 12.6 only
  • Broadcom Ca Identity Suite Virtual Appliance: from 14.0, up to and including 14.2

Published 2018-10-17. Last modified 2026-06-17.