Vulnerabilities
Vulnerable Software
Broadcom:  >> Siteminder  >> 12.0  Security Vulnerabilities
Cross-site scripting (XSS) vulnerability in CA SiteMinder 12.0 through 12.51, and SiteMinder 6 Web Agents, allows remote attackers to inject arbitrary web script or HTML via vectors involving a " (double quote) character.
CVSS Score
4.3
EPSS Score
0.003
Published
2013-10-29
The Web Agents component in CA SiteMinder R6 before SP6 CR2 and R12 before SP3 CR2 does not properly handle multi-line headers, which allows remote authenticated users to conduct impersonation attacks and gain privileges via crafted data.
CVSS Score
4.3
EPSS Score
0.008
Published
2011-04-27
CA SiteMinder allows remote attackers to bypass cross-site scripting (XSS) protections for J2EE applications via a request containing non-canonical, "overlong Unicode" in place of blacklisted characters.
CVSS Score
4.3
EPSS Score
0.004
Published
2009-08-11


Contact Us

Shodan ® - All rights reserved