CVE Vulnerabilities

CVE-2015-6854

Insufficient Verification of Data Authenticity

Published: Mar 24, 2016 | Modified: Apr 09, 2021
CVSS 3.x
9.1
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

The non-Domino web agents in CA Single Sign-On (aka SSO, formerly SiteMinder) R6, R12.0 before SP3 CR13, R12.0J before SP3 CR1.2, and R12.5 before CR5 allow remote attackers to cause a denial of service (daemon crash) or obtain sensitive information via a crafted request.

Weakness

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Affected Software

Name Vendor Start Version End Version
Single_sign-on Broadcom r6.0 (including) r6.0 (including)
Single_sign-on Broadcom r12.0 (including) r12.0 (including)
Single_sign-on Broadcom r12.0j (including) r12.0j (including)
Single_sign-on Broadcom r12.5 (including) r12.5 (including)

References