CVE-2011-1718

The Web Agents component in CA SiteMinder R6 before SP6 CR2 and R12 before SP3 CR2 does not properly handle multi-line headers, which allows remote authenticated users to conduct impersonation attacks and gain privileges via crafted data.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ca:siteminder:6:sp5_cr35:*:*:*:*:*:*
cpe:2.3:a:broadcom:siteminder:12.0:sp3:cr01:*:*:*:*:*

Information

Published : 2011-04-26 18:25

Updated : 2021-04-12 07:17


NVD link : CVE-2011-1718

Mitre link : CVE-2011-1718


JSON object : View

CWE
CWE-20

Improper Input Validation

Advertisement

dedicated server usa

Products Affected

ca

  • siteminder

broadcom

  • siteminder