Back to search
CVE-2011-1718
Published: Apr 27, 2011
Modified: Aug 6, 2024
PUBLISHED
Description
The Web Agents component in CA SiteMinder R6 before SP6 CR2 and R12 before SP3 CR2 does not properly handle multi-line headers, which allows remote authenticated users to conduct impersonation attacks and gain privileges via crafted data.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20110421 CA20110420-01: Security Notice for CA SiteMinder
mailing-list
x_refsource_BUGTRAQ
8227
third-party-advisory
x_refsource_SREASON
47520
vdb-entry
x_refsource_BID
ADV-2011-1067
vdb-entry
x_refsource_VUPEN
siteminder-headers-spoofing(66906)
vdb-entry
x_refsource_XF
1025423
vdb-entry
x_refsource_SECTRACK
44218
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now