CVE-2011-1718

The Web Agents component in CA SiteMinder R6 before SP6 CR2 and R12 before SP3 CR2 does not properly handle multi-line headers, which allows remote authenticated users to conduct impersonation attacks and gain privileges via crafted data.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ca:siteminder:6:sp5_cr35:*:*:*:*:*:*
cpe:2.3:a:broadcom:siteminder:12.0:sp3:cr01:*:*:*:*:*

Information

Published : 2011-04-27 01:25

Updated : 2021-04-12 14:17


NVD link : CVE-2011-1718

Mitre link : CVE-2011-1718


JSON object : View

Products Affected

ca

  • siteminder

broadcom

  • siteminder
CWE
CWE-20

Improper Input Validation