CVE-2011-1718

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
27/04/2011
Last modified:
11/04/2025

Description

The Web Agents component in CA SiteMinder R6 before SP6 CR2 and R12 before SP3 CR2 does not properly handle multi-line headers, which allows remote authenticated users to conduct impersonation attacks and gain privileges via crafted data.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:broadcom:siteminder:12.0:sp3:cr01:*:*:*:*:*
cpe:2.3:a:ca:siteminder:6:sp5_cr35:*:*:*:*:*:*