CA SiteMinder Security Notice

2011-05-01 / 2011-05-02
Risk: Low
Local: No
Remote: Yes
CWE: CWE-20


CVSS Base Score: 4.3/10
Impact Subscore: 2.9/10
Exploitability Subscore: 8.6/10
Exploit range: Remote
Attack complexity: Medium
Authentication: No required
Confidentiality impact: None
Integrity impact: Partial
Availability impact: None

CA20110420-01: Security Notice for CA SiteMinder Issued: April 20, 2011 CA Technologies support is alerting customers to a security risk associated with CA SiteMinder. A vulnerability exists that can allow a malicious user to impersonate another user. CA Technologies has issued patches to address the vulnerability. The vulnerability, CVE-2011-1718, is due to improper handling of multi-line headers. A malicious user can send specially crafted data to impersonate another user. Risk Rating Medium Platform Windows Affected Products CA SiteMinder R6 Web Agents prior to R6 SP6 CR2 CA SiteMinder R12 Web Agents prior to R12 SP3 CR2 How to determine if the installation is affected Check the Web Agent log to obtain the installed release version. Note that the "webagent.log" file name is configurable by the SiteMinder administrator. Solution CA has issued patches to address the vulnerability. CA SiteMinder R6: Upgrade to R6 SP6 CR2 or later CA SiteMinder R12: Upgrade to R12 SP3 CR2 or later CR releases can be found on the CA SiteMinder Hotfix / Cumulative Release page: (URL may wrap) support.ca.com/irj/portal/anonymous/phpdocs?filePath=0/5262/5262_fixinde x.html References CVE-2011-1718 - CA SiteMinder Multi-line Header Vulnerability Acknowledgement April King (april (at) twoevils (dot) org [email concealed]) Change History Version 1.0: Initial Release If additional information is required, please contact CA Technologies Support at https://support.ca.com. If you discover a vulnerability in a CA Technologies product, please report your findings to the CA Technologies Product Vulnerability Response Team. support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=177782

References:

https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=%7B1BF29B14-C5FB-4BD3-9113-68E2426E4381%7D
http://xforce.iss.net/xforce/xfdb/66906
http://www.vupen.com/english/advisories/2011/1067
http://www.securityfocus.com/bid/47520
http://www.securityfocus.com/archive/1/archive/1/517626/100/0/threaded
http://securitytracker.com/id?1025423
http://secunia.com/advisories/44218


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2018, cxsecurity.com

 

Back to Top