CA Service Catalog 17.2 and 17.3 contain a vulnerability in the default configuration of the Setup Utility that may allow a remote attacker to cause a denial of service condition.
Using an empty string as a password is insecure.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Ca_service_catalog | Broadcom | 17.2 (including) | 17.2 (including) |
| Ca_service_catalog | Broadcom | 17.3 (including) | 17.3 (including) |