First published: Tue Aug 11 2009(Updated: )
CA SiteMinder allows remote attackers to bypass cross-site scripting (XSS) protections for J2EE applications via a request containing non-canonical, "overlong Unicode" in place of blacklisted characters.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun J2ee | ||
Broadcom Siteminder | ||
All of | ||
Sun J2ee | ||
Broadcom Siteminder |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2705 is classified as a medium severity vulnerability.
To fix CVE-2009-2705, ensure that your CA SiteMinder is updated to a version that addresses this vulnerability.
CVE-2009-2705 affects J2EE applications integrated with CA SiteMinder.
CVE-2009-2705 allows remote attackers to bypass XSS protections using overlong Unicode requests.
CVE-2009-2705 is associated with Broadcom's CA SiteMinder and Sun J2EE.