Insecure Handling of Shared Secret Keys in CA API Developer Portal 4.3.1 and Earlier Allows Authorization Bypass

Insecure Handling of Shared Secret Keys in CA API Developer Portal 4.3.1 and Earlier Allows Authorization Bypass

CVE-2020-11658 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CA API Developer Portal 4.3.1 and earlier handles shared secret keys in an insecure manner, which allows attackers to bypass authorization.

Learn more about our Api Penetration Testing.