First published: Tue Aug 11 2009(Updated: )
CA SiteMinder allows remote attackers to bypass cross-site scripting (XSS) protections for J2EE applications via a request containing a %00 (encoded null byte).
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun J2ee | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2704 is classified as a medium severity vulnerability.
To fix CVE-2009-2704, ensure that your application properly sanitizes inputs to prevent null byte injection.
CVE-2009-2704 affects applications using Sun J2EE that implement CA SiteMinder security measures.
Yes, CVE-2009-2704 can be exploited remotely by attackers able to craft specific requests.
Exploiting CVE-2009-2704 may allow attackers to bypass cross-site scripting protections, leading to potential data exposure.