CVE-2011-1718: Input Validation
Published Apr 27, 2011
·Updated
The Web Agents component in CA SiteMinder R6 before SP6 CR2 and R12 before SP3 CR2 does not properly handle multi-line headers, which allows remote authenticated users to conduct impersonation attacks and gain privileges via crafted data.
Affected Software
2 affected components
CA SiteMinder=6-sp5_cr35
Broadcom Siteminder=12.0-sp3
Event History
Apr 27, 2011
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-1718?
CVE-2011-1718 is classified as a high severity vulnerability that could enable impersonation attacks.
2
How do I fix CVE-2011-1718?
To remediate CVE-2011-1718, upgrade CA SiteMinder to version R6 SP6 CR2 or R12 SP3 CR2 or later.
3
Who is affected by CVE-2011-1718?
CVE-2011-1718 affects CA SiteMinder versions prior to SP6 CR2 for R6 and SP3 CR2 for R12.
4
What type of attack does CVE-2011-1718 allow?
CVE-2011-1718 allows remote authenticated users to perform impersonation attacks.
5
What components of CA SiteMinder are impacted by CVE-2011-1718?
The vulnerability is in the Web Agents component of CA SiteMinder.