CVE-2020-11666
Description
CA API Developer Portal 4.3.1 and earlier contains an access control flaw that allows malicious users to elevate privileges.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An access control flaw in CA API Developer Portal 4.3.1 and earlier allows malicious users with low privileges to elevate their privileges, potentially gaining administrative control.
Vulnerability
CVE-2020-11666 is an access control flaw in the CA API Developer Portal versions 4.3.1 and earlier [1]. The vulnerability resides in the authorization logic, allowing a malicious user to bypass intended restrictions and elevate their privileges. The exact component or endpoint is not publicly detailed, but the flaw is present in the portal's access control enforcement [1].
Exploitation
An attacker must have a valid user account with low privileges on the portal [1]. The attacker then exploits the access control flaw by sending crafted requests that manipulate the authorization checks, causing the system to grant higher privileges than intended [1]. No user interaction is required beyond the attacker's own actions [1].
Impact
Successful exploitation allows the attacker to escalate their privileges to a higher level, potentially gaining administrative access [1]. This can lead to full control over the portal, including the ability to view, modify, or delete sensitive data, manage users, and perform other administrative actions [1].
Mitigation
Broadcom released a fix for this vulnerability in the CA API Developer Portal update announced on April 14, 2020 [1]. Customers should apply the vendor-supplied patch immediately. If patching is not possible, workarounds are not specified in the public advisory [1].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- CA/API Developer Portaldescription
- Range: <=4.3.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- packetstormsecurity.com/files/157244/CA-API-Developer-Portal-4.2.x-4.3.1-Access-Bypass-Privilege-Escalation.htmlmitrex_refsource_MISC
- packetstormsecurity.com/files/157276/CA-API-Developer-Portal-4.2.x-4.3.1-Access-Bypass-Privilege-Escalation.htmlmitrex_refsource_MISC
- seclists.org/fulldisclosure/2020/Apr/24mitremailing-listx_refsource_FULLDISC
- techdocs.broadcom.com/us/product-content/status/announcement-documents/2020/CA20200414-01-Securit-Notice-for-CA-API-Developer-Portal.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.