CVE-2015-6853

Severity CVSS v4.0:
Pending analysis
Type:
CWE-345 Insufficient Verification of Data Authenticity
Publication date:
24/03/2016
Last modified:
12/04/2025

Description

The Domino web agent in CA Single Sign-On (aka SSO, formerly SiteMinder) R6, R12.0 before SP3 CR13, R12.0J before SP3 CR1.2, R12.5 before CR5, R12.51 before CR4, and R12.52 before SP1 CR3 allows remote attackers to cause a denial of service (daemon crash) or obtain sensitive information via a crafted request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:broadcom:single_sign-on:r6.0:*:*:*:*:*:*:*
cpe:2.3:a:broadcom:single_sign-on:r12.0:*:*:*:*:*:*:*
cpe:2.3:a:broadcom:single_sign-on:r12.0j:*:*:*:*:*:*:*
cpe:2.3:a:broadcom:single_sign-on:r12.5:*:*:*:*:*:*:*
cpe:2.3:a:broadcom:single_sign-on:r12.51:*:*:*:*:*:*:*
cpe:2.3:a:broadcom:single_sign-on:r12.52:*:*:*:*:*:*:*