\.lang\.([A-Za-z0-9_]+)Exception in index.jsp
search cancel

\.lang\.([A-Za-z0-9_]+)Exception in index.jsp

book

Article ID: 243029

calendar_today

Updated On:

Products

CA Identity Suite

Issue/Introduction

Affected URL: https://example.domain.net/iam/im/IdentityEnv/ui7/index.jsp

The application displays detailed error messages when unhandled Java exceptions occur. Detailed technical error messages can allow an adversary to gain information about the application and database that could be used to conduct further attacks. The following expressions were matched in the HTTP response:

\.java:[0-9]+
\.lang\.([A-Za-z0-9_]+)Exception

 

Environment

Release : 14.3

Component : Identity Manager

Resolution

There is no known actual exposure of database information or other leaked information.

If you can provide a detailed explanation and CVE, along with instructions on exactly how a malicious attacker can cause a security breach please open a support case.