Netegrity SiteMinder before 4.11 allows remote attackers to bypass its authentication mechanism by appending $/FILENAME.ext (where ext is .ccc, .class, or .jpg) to the requested URL.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Siteminder | Netegrity | 3.6 (including) | 3.6 (including) |
Siteminder | Netegrity | 4.0 (including) | 4.0 (including) |