The non-Domino web agents in CA Single Sign-On (aka SSO, formerly SiteMinder) R6, R12.0 before SP3 CR13, R12.0J before SP3 CR1.2, and R12.5 before CR5 allow remote attackers to cause a denial of service (daemon crash) or obtain sensitive information via a crafted request.
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Single_sign-on | Broadcom | r6.0 (including) | r6.0 (including) |
Single_sign-on | Broadcom | r12.0 (including) | r12.0 (including) |
Single_sign-on | Broadcom | r12.0j (including) | r12.0j (including) |
Single_sign-on | Broadcom | r12.5 (including) | r12.5 (including) |