CA.Siteminder.Unicode.CSS.Protection.Security.Bypass

description-logoDescription

This indicates an attack attempt to exploit a Security Bypass vulnerability in Computer Associates SiteMinder.
This issue is caused by an error in the vulnerable software when handling a request with "overlong Unicode" in place of blacklisted characters. It may allow remote attackers to bypass the CSS protection via sending a crafted HTTP request.

affected-products-logoAffected Products

Computer Associates SiteMinder

Impact logoImpact

Security Bypass

recomended-action-logoRecommended Actions

Refer to the vendor's web site for suggested workaround.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2021-01-11 16.995