4.3
CVSSv2

CVE-2009-2704

Published: 11/08/2009 Updated: 14/02/2024
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

CA SiteMinder allows remote malicious users to bypass cross-site scripting (XSS) protections for J2EE applications via a request containing a %00 (encoded null byte).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sun j2ee

Exploits

source: wwwsecurityfocuscom/bid/36086/info Computer Associates SiteMinder is prone to a security-bypass vulnerability because it fails to properly validate user-supplied input An attacker can exploit this issue to bypass cross-site scripting protections Successful exploits can aid in further attacks We don't know which versions of Si ...