CVE-2024-36459: Cross-Site Scripting Vulnerability in Symantec SiteMinder Web Agent
A CRLF cross-site scripting vulnerability has been identified in certain configurations of the SiteMinder Web Agent for IIS Web Server and SiteMinder Web Agent for Domino Web Server. As a result, an attacker can execute arbitrary Javascript code in a client browser.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36459?
The severity of CVE-2024-36459 is classified as high due to the potential for arbitrary JavaScript execution.
How do I fix CVE-2024-36459?
To fix CVE-2024-36459, you should apply the latest security patches provided by Symantec for the affected SiteMinder Web Agents.
What types of web servers are affected by CVE-2024-36459?
CVE-2024-36459 affects configurations of the SiteMinder Web Agent for both IIS Web Server and Domino Web Server.
What does CVE-2024-36459 allow an attacker to do?
CVE-2024-36459 allows an attacker to execute arbitrary JavaScript code in a client's browser, leading to potential data theft or manipulation.
Is CVE-2024-36459 a cross-site scripting vulnerability?
Yes, CVE-2024-36459 is categorized as a CRLF cross-site scripting vulnerability.