Computer Associates SiteMinder User Impersonation Vulnerability
BID:47520
Info
Computer Associates SiteMinder User Impersonation Vulnerability
| Bugtraq ID: | 47520 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-1718 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 21 2011 12:00AM |
| Updated: | May 19 2011 03:42PM |
| Credit: | Vendor reported this issue |
| Vulnerable: |
Computer Associates SiteMinder Web Agent 6.0 SP5 CR35 Computer Associates SiteMinder Web Agent 12.0 SP2 CR1 |
| Not Vulnerable: |
Computer Associates SiteMinder Web Agent R6 SP6 CR2 Computer Associates SiteMinder Web Agent R12 SP3 CR2 |
Discussion
Computer Associates SiteMinder User Impersonation Vulnerability
Computer Associates SiteMinder is prone to a user-impersonation vulnerability because it fails to properly handle multi-line headers.
An attacker can exploit this issue to impersonate arbitrary users, sending potentially malicious and misleading messages from arbitrary users.
The following versions are affected:
CA SiteMinder R6 Web Agents versions prior to R6 SP6 CR2
CA SiteMinder R12 Web Agents versions prior to R12 SP3 CR2
NOTE: This issue only affects SiteMinder Web Agents for Microsoft Internet Information Services (IIS) 6.0.
Computer Associates SiteMinder is prone to a user-impersonation vulnerability because it fails to properly handle multi-line headers.
An attacker can exploit this issue to impersonate arbitrary users, sending potentially malicious and misleading messages from arbitrary users.
The following versions are affected:
CA SiteMinder R6 Web Agents versions prior to R6 SP6 CR2
CA SiteMinder R12 Web Agents versions prior to R12 SP3 CR2
NOTE: This issue only affects SiteMinder Web Agents for Microsoft Internet Information Services (IIS) 6.0.
Exploit / POC
Computer Associates SiteMinder User Impersonation Vulnerability
Attackers can exploit this issue via a browser.
Attackers can exploit this issue via a browser.
Solution / Fix
Computer Associates SiteMinder User Impersonation Vulnerability
Solution:
Reports indicate that the vendor has resolved this issue. Please contact the vendor for details.
Solution:
Reports indicate that the vendor has resolved this issue. Please contact the vendor for details.
References
Computer Associates SiteMinder User Impersonation Vulnerability
References:
References:
- CA SiteMinder Hotfix/Cumulative Release Index (Computer Associates)
- SiteMinder Homepage (Computer Associates)