VendorsBroadcomsiteminderall versions
Vulnerabilities

Broadcom SiteMinder

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2009-2705
CA SiteMinder allows remote attackers to bypass cross-site scripting (XSS) protections for J2EE applications via a request containing non-canonical, "overlong Unicode" in place of blacklisted characters.
Published 2009-08-11 · Modified
4.31 PoCEPSS 0.044
CVE-2013-5968
Cross-site scripting (XSS) vulnerability in CA SiteMinder 12.0 through 12.51, and SiteMinder 6 Web Agents, allows remote attackers to inject arbitrary web script or HTML via vectors involving a " (double quote) character.
Published 2013-10-29 · Modified
4.3EPSS 0.026
CVE-2011-1718
The Web Agents component in CA SiteMinder R6 before SP6 CR2 and R12 before SP3 CR2 does not properly handle multi-line headers, which allows remote authenticated users to conduct impersonation attacks and gain privileges via crafted data.
Published 2011-04-27 · Modified
4.3EPSS 0.024