CVE-2009-2705: XSS
Published Aug 11, 2009
·Updated
CA SiteMinder allows remote attackers to bypass cross-site scripting (XSS) protections for J2EE applications via a request containing non-canonical, "overlong Unicode" in place of blacklisted characters.
Affected Software
4 affected components
Sun J2EE
Broadcom Siteminder
All of the following
Sun J2EE
Broadcom Siteminder
Event History
Aug 11, 2009
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
10:30 AM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-2705?
CVE-2009-2705 is classified as a medium severity vulnerability.
2
How do I fix CVE-2009-2705?
To fix CVE-2009-2705, ensure that your CA SiteMinder is updated to a version that addresses this vulnerability.
3
What types of applications are affected by CVE-2009-2705?
CVE-2009-2705 affects J2EE applications integrated with CA SiteMinder.
4
What attack vector is exploited in CVE-2009-2705?
CVE-2009-2705 allows remote attackers to bypass XSS protections using overlong Unicode requests.
5
Who is the vendor associated with CVE-2009-2705?
CVE-2009-2705 is associated with Broadcom's CA SiteMinder and Sun J2EE.