PT-2000-1773 · Netegrity · Netegrity Siteminder

Published

2000-11-14

·

Updated

2017-10-10

·

CVE-2000-0850

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Netegrity SiteMinder versions prior to 4.11
Description The issue allows remote attackers to bypass the authentication mechanism. This can be achieved by appending "$/FILENAME.ext" (where ext is .ccc, .class, or .jpg) to the requested URL.
Recommendations For versions prior to 4.11, update to version 4.11 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2000-0850

Affected Products

Netegrity Siteminder