First published: Tue Nov 14 2000(Updated: )
Netegrity SiteMinder before 4.11 allows remote attackers to bypass its authentication mechanism by appending "$/FILENAME.ext" (where ext is .ccc, .class, or .jpg) to the requested URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netegrity Policy Server | =4.0 | |
Netegrity Policy Server | =3.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0850 is considered to have a high severity as it allows remote attackers to bypass authentication mechanisms.
To mitigate CVE-2000-0850, upgrade Netegrity SiteMinder to version 4.11 or later where the vulnerability is patched.
CVE-2000-0850 affects Netegrity SiteMinder versions prior to 4.11, specifically versions 3.6 and 4.0.
Attackers exploit CVE-2000-0850 by appending specific file extensions to the authenticated URL to bypass security.
While CVE-2000-0850 pertains to older software versions, it remains relevant for systems that have not been properly updated.