PT-2000-1773 · Netegrity · Netegrity Siteminder

Publicado

2000-11-14

·

Atualizado

2017-10-10

·

CVE-2000-0850

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Netegrity SiteMinder versions prior to 4.11
Description The issue allows remote attackers to bypass the authentication mechanism. This can be achieved by appending "$/FILENAME.ext" (where ext is .ccc, .class, or .jpg) to the requested URL.
Recommendations For versions prior to 4.11, update to version 4.11 or later to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2000-0850

Produtos afetados

Netegrity Siteminder