CVE-2011-1718

The Web Agents component in CA SiteMinder R6 before SP6 CR2 and R12 before SP3 CR2 does not properly handle multi-line headers, which allows remote authenticated users to conduct impersonation attacks and gain privileges via crafted data.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:broadcom:siteminder:12.0:sp3:cr01:*:*:*:*:*
cpe:2.3:a:ca:siteminder:6:sp5_cr35:*:*:*:*:*:*

History

No history.

Information

Published : 2011-04-27 01:25

Updated : 2024-02-04 17:54


NVD link : CVE-2011-1718

Mitre link : CVE-2011-1718

CVE.ORG link : CVE-2011-1718


JSON object : View

Products Affected

ca

  • siteminder

broadcom

  • siteminder
CWE
CWE-20

Improper Input Validation