Open Redirect Vulnerability in CA API Developer Portal
CVE-2020-11665
6.1MEDIUM
Summary
The CA API Developer Portal versions up to 4.3.1 contains a vulnerability that allows an attacker to exploit insecure handling of the loginRedirect page. This vulnerability could enable malicious actors to redirect users to any arbitrary site, potentially leading to phishing attacks or further exploitation of user data. Ensuring that proper validation and sanitization of redirect URLs are implemented can mitigate this security risk.
Affected Version(s)
CA API Developer Portal 4.3.1 and earlier
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved