Access Control Flaw in CA API Developer Portal by Broadcom
CVE-2020-11666
8.8HIGH
Summary
A significant access control flaw exists in CA API Developer Portal versions 4.3.1 and earlier, which may allow unauthorized users to elevate their privileges. This vulnerability can be exploited by attackers to gain access to restricted areas of the application, potentially compromising sensitive data and system integrity. Administrators are urged to review their implementations and apply necessary updates to mitigate risks associated with this flaw.
Affected Version(s)
CA API Developer Portal 4.3.1 and earlier
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved